Threat reportVulnerabilityTL-2026-0240
HPE Aruba AOS-CX Pre-Auth Admin Password Reset (CVE-2026-23813)
HPE Aruba AOS-CX Pre-Auth Admin Password Reset (TL-2026-0240), also tracked as HPESBNW04848, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-17. It has no confirmed attribution, affects Hewlett Packard Enterprise Aruba CX 4100i Series Switches, references 1 CVE (CVE-2026-23813), maps to 11 MITRE ATT&CK techniques (T1021, T1040, T1046), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0240
- Threat ID
- TL-2026-0240
- Also known as
- HPESBNW04848, GHSA-37q7-686v-7f32
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- enterprise, government, financial, healthcare, education, telecommunications, manufacturing, energy, retail, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in HPE Aruba AOS-CX Pre-Auth Admin Password Reset
Malware and tooling: curl/wget/httpie targeting AOS-CX REST API
How HPE Aruba AOS-CX Pre-Auth Admin Password Reset works
Critical authentication bypass (CVSS 9.8) in the web-based management interface of HPE Aruba AOS-CX switches allows unauthenticated remote attackers to circumvent authentication controls and reset administrator passwords. Affects 11 CX switch series across 4 firmware branches, enabling full device takeover of enterprise network infrastructure.
CVE-2026-23813 is a critical authentication bypass vulnerability in the web-based management interface of HPE Aruba Networking AOS-CX switches. The flaw allows an unauthenticated remote attacker to circumvent existing authentication controls and, in some cases, reset the administrator password of the device, granting full administrative control over the affected switch.
The vulnerability resides in the HTTP/HTTPS management interface and can be exploited remotely with low attack complexity, requiring no authentication or user interaction. The CVSS 3.1 base score of 9.8 reflects the severity: network attack vector, no privileges required, and high impact across confidentiality, integrity, and availability.
Affected hardware spans 11 HPE Aruba CX switch series: CX 4100i, CX 6000, CX 6100, CX 6200, CX 6300, CX 6400, CX 8320, CX 8325, CX 8360, CX 9300, and CX 10000. These switches are widely deployed in enterprise campus and data center environments, making the attack surface significant. Four firmware branches are affected: AOS-CX 10.10.xxxx (10.10.1170 and earlier), 10.13.xxxx (10.13.1160 and earlier), 10.16.xxxx (10.16.1020 and earlier), and 10.17.xxxx (10.17.0001 and earlier).
The vulnerability was discovered by security researcher 'moonv' through the HPE Aruba Networking Bug Bounty Program and disclosed on March 11, 2026 via HPE Security Advisory HPESBNW04848. At the time of disclosure, HPE stated it was not aware of any public exploitation or proof-of-concept code targeting the vulnerability.
Critically, CVE-2026-23813 can be chained with CVE-2026-23814 (CVSS 8.8), an authenticated command injection flaw in the same AOS-CX platform. This creates a devastating attack chain: the authentication bypass provides initial access, and the command injection enables arbitrary command execution on the switch operating system. Together, they enable full remote code execution on enterprise network infrastructure without any prior credentials.
Three additional high-severity vulnerabilities were disclosed alongside CVE-2026-23813: CVE-2026-23815 (CVSS 7.2, high-privilege command injection), CVE-2026-23816 (CVSS 7.2, CLI command injection), and CVE-2026-23817 (CVSS 6.5, open redirect). All are addressed in the same firmware updates.
HPE released patched firmware versions: AOS-CX 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180. Organizations unable to immediately patch should isolate management interfaces on dedicated VLANs, restrict access to trusted hosts via Layer 3 ACLs and Control Plane ACLs, disable HTTP/HTTPS management on unnecessary ports, and enable comprehensive logging and monitoring for unauthorized access attempts.
The CWE classification is CWE-287 (Improper Authentication), as identified by CISA-ADP. The vulnerability represents a significant risk to organizations relying on Aruba CX switches for critical network infrastructure, particularly given the low complexity of exploitation and the potential for full device takeover leading to traffic interception, network persistence, and lateral movement.
MITRE ATT&CK techniques used in TL-2026-0240
lateral-movement
credential-access
T1040 Network Sniffing; T1556 Modify Authentication Process
discovery
T1046 Network Service Discovery
execution
T1059 Command and Scripting Interpreter
defense-evasion
T1070 Indicator Removal; T1078 Valid Accounts
command-and-control
T1071 Application Layer Protocol
initial-access
T1190 Exploit Public-Facing Application
impact
T1498 Network Denial of Service
reconnaissance
Affected products and versions in HPE Aruba AOS-CX Pre-Auth Admin Password Reset
- Hewlett Packard Enterprise — Aruba CX 4100i Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 6000 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 6100 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 6200 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 6300 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 6400 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 8320 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 8325 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 8360 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001 - Hewlett Packard Enterprise — Aruba CX 9300 Series Switches
Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
Remediation for HPE Aruba AOS-CX Pre-Auth Admin Password Reset
Patches
- Upgrade to AOS-CX 10.17.1001 or later (for 10.17.xxxx branch)
- Upgrade to AOS-CX 10.16.1030 or later (for 10.16.xxxx branch)
- Upgrade to AOS-CX 10.13.1161 or later (for 10.13.xxxx branch)
- Upgrade to AOS-CX 10.10.1180 or later (for 10.10.xxxx branch)
Immediate actions
- Isolate AOS-CX switch management interfaces on dedicated VLANs inaccessible from general network segments
- Restrict HTTP/HTTPS management access to trusted administrator hosts via Layer 3 ACLs
- Implement Control Plane ACLs to limit REST API and HTTPS access to authorized management stations
- Disable HTTP/HTTPS management interfaces on all ports where web management is not required
- Enable comprehensive logging and monitoring on all AOS-CX switches to detect unauthorized access attempts
- Audit administrative accounts for any unauthorized password changes or new account creation
Workarounds
- Disable web-based management interface entirely and manage switches via SSH/CLI only
- Restrict management interface access to a dedicated out-of-band management network
- Apply Control Plane ACLs to block unauthenticated HTTP/HTTPS access to switch management
- Enable RADIUS/TACACS+ for switch management authentication as an additional authentication layer
Longer-term hardening
- Deploy network access control (NAC) to enforce management plane segmentation
- Implement out-of-band management networks for all critical network infrastructure
- Deploy SIEM rules to detect anomalous authentication patterns on network switch management interfaces
- Establish firmware update policies for rapid deployment of critical security patches on network infrastructure
- Conduct regular vulnerability assessments of network infrastructure management planes
CVEs associated with HPE Aruba AOS-CX Pre-Auth Admin Password Reset
Weaknesses (CWE) in HPE Aruba AOS-CX Pre-Auth Admin Password Reset
Timeline of HPE Aruba AOS-CX Pre-Auth Admin Password Reset
- GitHub Advisory GHSA-37q7-686v-7f32 published for CVE-2026-23813
- CVE-2026-23813 published to NVD with CVSS 9.8 Critical rating and CWE-287 classification
- HPE releases patched AOS-CX firmware versions 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180
- HPE publishes Security Advisory HPESBNW04848 disclosing CVE-2026-23813 and four related AOS-CX vulnerabilities
- CERT-IN and INCIBE-CERT publish advisories CIVN-2026-0137 and CVE-2026-23813 respectively
- CyCognito publishes analysis of CVE-2026-23813 and CVE-2026-23814 attack chain enabling pre-auth RCE
- Major security publications (SecurityWeek, BleepingComputer, Security Affairs, TechRadar, SC Media) report on CVE-2026-23813
- Threadlinqs Intelligence publishes full threat analysis TL-2026-0240 with detection rules and simulation coverage
- As of 2026-05-29, CVE-2026-23813 (CVSS 9.8 Aruba AOS-CX pre-auth admin password reset) remains PATCHED, with HPE fixes available across all four firmware branches since the March 11 disclosure. HPE, BleepingComputer, SecurityWeek and CSO Online report no in-the-wild exploitation, no public PoC, no CISA KEV listing, and the flaw is unattributed (bug-bounty discovery by "moonv").
Sources cited for HPE Aruba AOS-CX Pre-Auth Admin Password Reset
- HPE Security Advisory HPESBNW04848 — AOS-CX Authentication Bypass
- NVD — CVE-2026-23813
- GitHub Advisory Database — GHSA-37q7-686v-7f32
- CyCognito — Emerging Threat: HPE AOS-CX Pre-Auth RCE Chain (CVE-2026-23813 / CVE-2026-23814)
- SecurityWeek — Critical HPE AOS-CX Vulnerability Allows Admin Password Resets
- BleepingComputer — HPE Warns of Critical AOS-CX Flaw Allowing Admin Password Resets
- Security Online — Critical 9.8 CVSS Bypass Unearthed in HPE Aruba AOS-CX Switches
- Security Affairs — HPE Fixes Critical Authentication Bypass in Aruba AOS-CX
- Field Effect — Critical Authentication Bypass in Aruba AOS-CX Impacts CX-Series Switches
- SC Media — HPE Aruba AOS-CX Vulnerabilities Addressed Including Critical Password Reset Flaw
- TechRadar — HPE Warns of Dangerous Security Flaw Allowing Aruba OS Password Resets
- INCIBE-CERT — CVE-2026-23813
- CERT-IN CIVN-2026-0137 — Multiple Vulnerabilities in HPE Aruba Networking AOS-CX
Detection coverage for TL-2026-0240
As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0240 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.