Description
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
13.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (5)
Hewlett Packard Enterprise (HPE)/AOS-CX
10.10.0000 - 10.10.1170
Hewlett Packard Enterprise (HPE)/AOS-CX
10.13.0000 - 10.13.1101
Hewlett Packard Enterprise (HPE)/AOS-CX
10.13.0000 - 10.13.1160
Hewlett Packard Enterprise (HPE)/AOS-CX
10.16.0000 - 10.16.1020
Hewlett Packard Enterprise (HPE)/AOS-CX
10.17.0000 - 10.17.0001
Published
Mar 11, 2026
Tracked Since
Mar 11, 2026