5.3
CVE-2026-23822
- EPSS 0.07%
- Veröffentlicht 12.05.2026 18:37:08
- Zuletzt bearbeitet 13.05.2026 15:35:17
- Quelle security-alert@hpe.com
- CVE-Watchlists
- Unerledigt
Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service
A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerHewlett Packard Enterprise (HPE)
≫
Produkt
ArubaOS (AOS)
Default Statusaffected
Version <=
8.13.1.1
Version
8.13.0.0
Status
affected
Version <=
8.12.0.6
Version
8.12.0.0
Status
affected
Version <=
8.10.0.21
Version
8.10.0.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.214 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-alert@hpe.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.