HPE has released security updates for a critical authentication bypass vulnerability (CVE-2026-23813) in the AOS-CX network operating system. The flaw allows an unauthenticated remote attacker to bypass authentication controls and, in some cases, reset the administrator password, potentially leading to full control over affected Aruba CX-series switches.
Vulnerability Details (CVE-2026-23813)
- Severity: Critical (CVSS v3.1 Base Score: 9.8).
- Impact: Full administrative takeover. Attackers can modify network configurations, intercept traffic, or disrupt operations.
- Attack Vector: Remote, over the network, with low complexity and no user interaction required.
- Discovery: Reported by researcher moonv through the HPE Aruba Networking Bug Bounty program.
Affected AOS-CX Versions
The vulnerability impacts the web-based management interface across several software branches:
- 10.17.xxxx: 10.17.0001 and below
- 10.16.xxxx: 10.16.1020 and below
- 10.13.xxxx: 10.13.1160 and below
- 10.10.xxxx: 10.10.1170 and below
Recommended Resolutions
HPE urges administrators to upgrade to the following fixed versions immediately:
- AOS-CX 10.17.1001 or higher
- AOS-CX 10.16.1030 or higher
- AOS-CX 10.13.1161 or higher
- AOS-CX 10.10.1180 or higher
Mitigation Workarounds
If immediate patching is not possible, implement these measures to reduce exposure:
- Isolate Management: Move all management interfaces to a dedicated, isolated Management VLAN (Layer 2).
- Restrict Access: Use Access Control Lists (ACLs) to permit only trusted hosts to reach the HTTPS/REST management endpoints.
- Disable Web UI: Disable HTTP/HTTPS management interfaces on ports where they are not strictly required.
- Monitor Activity: Enable comprehensive logging and accounting to detect unauthorized access attempts.