CVE-2026-23813

CRITICAL

AOS-CX - Auth Bypass

Title source: llm

Description

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-287
Status draft

Timeline

Published Mar 11, 2026
Tracked Since Mar 11, 2026