Skip to content

HPE Aruba Networking Security Advisory

Security Advisory: HPE Aruba Networking AOS-CX

HPE has disclosed several vulnerabilities in the AOS-CX network operating system. Successful exploitation could allow adversaries to bypass authentication or execute arbitrary commands on the underlying OS.

CRITICAL NOTICE: CVE-2026-23813 allows unauthenticated remote adversaries to reset the administrator password. Immediate patching is required.
 

Vulnerability Summary

CVE IDTypeCVSS
CVE-2026-23813Authentication Bypass9.8
CVE-2026-23814CLI Command Injection8.8
CVE-2026-23815Binary Command Injection7.2
CVE-2026-23816OS Command Injection7.2
CVE-2026-23817Open Redirect6.5

 

Remediation Steps

Update to the following versions or later to resolve these issues:

  • AOS-CX 10.10.xxxx: Upgrade to 10.10.1180
  • AOS-CX 10.13.xxxx: Upgrade to 10.13.1161
  • AOS-CX 10.16.xxxx: Upgrade to 10.16.1030
  • AOS-CX 10.17.xxxx: Upgrade to 10.17.1001

 

Asset Identification (runZero)

To locate potentially vulnerable systems in your inventory, use the following query:

hw:=”HPE Aruba CX%” AND protocol:http

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Discover more from Version 2 Limited

Subscribe now to keep reading and get access to the full archive.

Continue reading