CVE-2026-23814
- EPSS 0.56%
- Veröffentlicht 11.03.2026 03:11:34
- Zuletzt bearbeitet 22.09.2026 20:01:22
A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
CVE-2026-23813
- EPSS 0.74%
- Veröffentlicht 11.03.2026 03:08:43
- Zuletzt bearbeitet 22.09.2026 20:00:30
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the ad...
CVE-2025-37160
- EPSS 0.29%
- Veröffentlicht 18.11.2025 18:54:09
- Zuletzt bearbeitet 04.12.2025 18:18:12
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker ...
CVE-2025-37159
- EPSS 0.26%
- Veröffentlicht 18.11.2025 18:52:46
- Zuletzt bearbeitet 04.12.2025 18:19:18
A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized acces...
CVE-2025-37158
- EPSS 0.66%
- Veröffentlicht 18.11.2025 18:51:28
- Zuletzt bearbeitet 04.12.2025 18:19:59
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
CVE-2025-37157
- EPSS 0.66%
- Veröffentlicht 18.11.2025 18:48:58
- Zuletzt bearbeitet 04.12.2025 18:20:14
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
CVE-2025-37156
- EPSS 0.3%
- Veröffentlicht 18.11.2025 18:46:10
- Zuletzt bearbeitet 04.12.2025 18:20:51
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and e...
CVE-2025-37155
- EPSS 0.12%
- Veröffentlicht 18.11.2025 18:40:40
- Zuletzt bearbeitet 04.12.2025 18:21:05
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges...
CVE-2025-25040
- EPSS 0.14%
- Veröffentlicht 18.03.2025 18:59:54
- Zuletzt bearbeitet 22.09.2026 19:57:07
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.1000 and below ...
CVE-2024-54010
- EPSS 0.24%
- Veröffentlicht 08.01.2025 21:15:12
- Zuletzt bearbeitet 22.09.2026 19:55:19
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be su...