An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system resources. Successful exploitation could result in unauthorized access or denial of service affecting the management interface.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Aruba Networking AOS-CX software to one of the following versions (as applicable):
- AOS-CX 10.10.1181 and above
- AOS-CX 10.13.1190 and above
- AOS-CX 10.16.1060 and above
- AOS-CX 10.17.1030 and above
- AOS-CX 10.18.1002 and above
Software versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.
Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation. | Sep 2, 2026 | Sep 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub