CVE-2026-23813

CRITICAL

AOS-CX - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-287
Status published
Products (5)
Hewlett Packard Enterprise (HPE)/AOS-CX 10.10.0000 - 10.10.1170
Hewlett Packard Enterprise (HPE)/AOS-CX 10.13.0000 - 10.13.1101
Hewlett Packard Enterprise (HPE)/AOS-CX 10.13.0000 - 10.13.1160
Hewlett Packard Enterprise (HPE)/AOS-CX 10.16.0000 - 10.16.1020
Hewlett Packard Enterprise (HPE)/AOS-CX 10.17.0000 - 10.17.0001
Published Mar 11, 2026
Tracked Since Mar 11, 2026