CVE-2026-23813
CVSS 9.8 CRITICAL: a vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially…
Vulnerabilities · 185 days ago
An unauthenticated critical vulnerability (CVE-2026-23813, CVSS 9.8) in the Aruba AOS‑CX web management interface allows remote actors to reset administrator passwords.
CVSS 9.8 CRITICAL: a vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially…
1 source covering this story
Critical HPE AOS-CX Vulnerability Allows Admin Password Resets
The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.
Part of the PlainSec briefing for 2026-03-15