CVE-2026-23596

MEDIUM

Aruba Networking Private 5G Core 1.24.3.0-1.24.3.2 - Unauthenticated Denial of Service via Management API

Title source: llm
STIX 2.1

Description

A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (1)
hpe/aruba_networking_private_5g_core 1.24.3.0 - 1.24.3.3
Published Feb 17, 2026
Tracked Since Feb 18, 2026