Threat reportVulnerabilityTL-2026-0240

HPE Aruba AOS-CX Pre-Auth Admin Password Reset (CVE-2026-23813)

criticalPATCHED

HPE Aruba AOS-CX Pre-Auth Admin Password Reset (TL-2026-0240), also tracked as HPESBNW04848, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-03-17. It has no confirmed attribution, affects Hewlett Packard Enterprise Aruba CX 4100i Series Switches, references 1 CVE (CVE-2026-23813), maps to 11 MITRE ATT&CK techniques (T1021, T1040, T1046), and is covered by 9 detection rules and 15 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0240

Threat ID
TL-2026-0240
Also known as
HPESBNW04848, GHSA-37q7-686v-7f32
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
enterprise, government, financial, healthcare, education, telecommunications, manufacturing, energy, retail, technology
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in HPE Aruba AOS-CX Pre-Auth Admin Password Reset

Malware and tooling: curl/wget/httpie targeting AOS-CX REST API

How HPE Aruba AOS-CX Pre-Auth Admin Password Reset works

Critical authentication bypass (CVSS 9.8) in the web-based management interface of HPE Aruba AOS-CX switches allows unauthenticated remote attackers to circumvent authentication controls and reset administrator passwords. Affects 11 CX switch series across 4 firmware branches, enabling full device takeover of enterprise network infrastructure.

CVE-2026-23813 is a critical authentication bypass vulnerability in the web-based management interface of HPE Aruba Networking AOS-CX switches. The flaw allows an unauthenticated remote attacker to circumvent existing authentication controls and, in some cases, reset the administrator password of the device, granting full administrative control over the affected switch.

The vulnerability resides in the HTTP/HTTPS management interface and can be exploited remotely with low attack complexity, requiring no authentication or user interaction. The CVSS 3.1 base score of 9.8 reflects the severity: network attack vector, no privileges required, and high impact across confidentiality, integrity, and availability.

Affected hardware spans 11 HPE Aruba CX switch series: CX 4100i, CX 6000, CX 6100, CX 6200, CX 6300, CX 6400, CX 8320, CX 8325, CX 8360, CX 9300, and CX 10000. These switches are widely deployed in enterprise campus and data center environments, making the attack surface significant. Four firmware branches are affected: AOS-CX 10.10.xxxx (10.10.1170 and earlier), 10.13.xxxx (10.13.1160 and earlier), 10.16.xxxx (10.16.1020 and earlier), and 10.17.xxxx (10.17.0001 and earlier).

The vulnerability was discovered by security researcher 'moonv' through the HPE Aruba Networking Bug Bounty Program and disclosed on March 11, 2026 via HPE Security Advisory HPESBNW04848. At the time of disclosure, HPE stated it was not aware of any public exploitation or proof-of-concept code targeting the vulnerability.

Critically, CVE-2026-23813 can be chained with CVE-2026-23814 (CVSS 8.8), an authenticated command injection flaw in the same AOS-CX platform. This creates a devastating attack chain: the authentication bypass provides initial access, and the command injection enables arbitrary command execution on the switch operating system. Together, they enable full remote code execution on enterprise network infrastructure without any prior credentials.

Three additional high-severity vulnerabilities were disclosed alongside CVE-2026-23813: CVE-2026-23815 (CVSS 7.2, high-privilege command injection), CVE-2026-23816 (CVSS 7.2, CLI command injection), and CVE-2026-23817 (CVSS 6.5, open redirect). All are addressed in the same firmware updates.

HPE released patched firmware versions: AOS-CX 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180. Organizations unable to immediately patch should isolate management interfaces on dedicated VLANs, restrict access to trusted hosts via Layer 3 ACLs and Control Plane ACLs, disable HTTP/HTTPS management on unnecessary ports, and enable comprehensive logging and monitoring for unauthorized access attempts.

The CWE classification is CWE-287 (Improper Authentication), as identified by CISA-ADP. The vulnerability represents a significant risk to organizations relying on Aruba CX switches for critical network infrastructure, particularly given the low complexity of exploitation and the potential for full device takeover leading to traffic interception, network persistence, and lateral movement.

MITRE ATT&CK techniques used in TL-2026-0240

lateral-movement

T1021 Remote Services

credential-access

T1040 Network Sniffing; T1556 Modify Authentication Process

discovery

T1046 Network Service Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts

command-and-control

T1071 Application Layer Protocol

initial-access

T1190 Exploit Public-Facing Application

impact

T1498 Network Denial of Service

reconnaissance

T1595 Active Scanning

Affected products and versions in HPE Aruba AOS-CX Pre-Auth Admin Password Reset

  • Hewlett Packard Enterprise — Aruba CX 4100i Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 6000 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 6100 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 6200 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 6300 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 6400 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 8320 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 8325 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 8360 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001
  • Hewlett Packard Enterprise — Aruba CX 9300 Series Switches
    Vulnerable versions: AOS-CX 10.10.1170 and earlier; AOS-CX 10.13.1160 and earlier; AOS-CX 10.16.1020 and earlier; AOS-CX 10.17.0001 and earlier
    Fixed in: AOS-CX 10.10.1180; AOS-CX 10.13.1161; AOS-CX 10.16.1030; AOS-CX 10.17.1001

Remediation for HPE Aruba AOS-CX Pre-Auth Admin Password Reset

Patches

  • Upgrade to AOS-CX 10.17.1001 or later (for 10.17.xxxx branch)
  • Upgrade to AOS-CX 10.16.1030 or later (for 10.16.xxxx branch)
  • Upgrade to AOS-CX 10.13.1161 or later (for 10.13.xxxx branch)
  • Upgrade to AOS-CX 10.10.1180 or later (for 10.10.xxxx branch)

Immediate actions

  • Isolate AOS-CX switch management interfaces on dedicated VLANs inaccessible from general network segments
  • Restrict HTTP/HTTPS management access to trusted administrator hosts via Layer 3 ACLs
  • Implement Control Plane ACLs to limit REST API and HTTPS access to authorized management stations
  • Disable HTTP/HTTPS management interfaces on all ports where web management is not required
  • Enable comprehensive logging and monitoring on all AOS-CX switches to detect unauthorized access attempts
  • Audit administrative accounts for any unauthorized password changes or new account creation

Workarounds

  • Disable web-based management interface entirely and manage switches via SSH/CLI only
  • Restrict management interface access to a dedicated out-of-band management network
  • Apply Control Plane ACLs to block unauthenticated HTTP/HTTPS access to switch management
  • Enable RADIUS/TACACS+ for switch management authentication as an additional authentication layer

Longer-term hardening

  • Deploy network access control (NAC) to enforce management plane segmentation
  • Implement out-of-band management networks for all critical network infrastructure
  • Deploy SIEM rules to detect anomalous authentication patterns on network switch management interfaces
  • Establish firmware update policies for rapid deployment of critical security patches on network infrastructure
  • Conduct regular vulnerability assessments of network infrastructure management planes

CVEs associated with HPE Aruba AOS-CX Pre-Auth Admin Password Reset

CVE-2026-23813

Weaknesses (CWE) in HPE Aruba AOS-CX Pre-Auth Admin Password Reset

CWE-287

Timeline of HPE Aruba AOS-CX Pre-Auth Admin Password Reset

  • GitHub Advisory GHSA-37q7-686v-7f32 published for CVE-2026-23813
  • CVE-2026-23813 published to NVD with CVSS 9.8 Critical rating and CWE-287 classification
  • HPE releases patched AOS-CX firmware versions 10.17.1001, 10.16.1030, 10.13.1161, and 10.10.1180
  • HPE publishes Security Advisory HPESBNW04848 disclosing CVE-2026-23813 and four related AOS-CX vulnerabilities
  • CERT-IN and INCIBE-CERT publish advisories CIVN-2026-0137 and CVE-2026-23813 respectively
  • CyCognito publishes analysis of CVE-2026-23813 and CVE-2026-23814 attack chain enabling pre-auth RCE
  • Major security publications (SecurityWeek, BleepingComputer, Security Affairs, TechRadar, SC Media) report on CVE-2026-23813
  • Threadlinqs Intelligence publishes full threat analysis TL-2026-0240 with detection rules and simulation coverage
  • As of 2026-05-29, CVE-2026-23813 (CVSS 9.8 Aruba AOS-CX pre-auth admin password reset) remains PATCHED, with HPE fixes available across all four firmware branches since the March 11 disclosure. HPE, BleepingComputer, SecurityWeek and CSO Online report no in-the-wild exploitation, no public PoC, no CISA KEV listing, and the flaw is unattributed (bug-bounty discovery by "moonv").

Sources cited for HPE Aruba AOS-CX Pre-Auth Admin Password Reset

Detection coverage for TL-2026-0240

As of 2026-03-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0240 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats