HarborGuard / CVE
Back to search
CRITICALCVE-2026-23813Published Modified CNA hpe

CVE-2026-23813: Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Hewlett Packard Enterprise (HPE) / AOS-CX
    ≤ 10.17.0001 · ≤ 10.16.1020 · ≤ 10.13.1160 · ≤ 10.10.1170
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References