CVE-2026-23813
CVSS 9.8 CRITICAL: a vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially…
Vulnerabilities & Exploits
An unauthenticated critical vulnerability (CVE-2026-23813, CVSS 9.8) in the Aruba AOS‑CX web management interface allows remote actors to reset administrator passwords.
1 source · Mar 14
CVSS 9.8 CRITICAL: a vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially…
SecurityWeek
Critical HPE AOS-CX Vulnerability Allows Admin Password Resets
The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.
originalPart of the PlainSec briefing for 2026-03-15
Every edition of this story: Critical Flaw Lets Remote Actors Reset Admin Passwords on Aruba Switches