CRITICALCVE-2026-23813Published Modified CNA hpe
CVE-2026-23813: Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
Affected packages
- Hewlett Packard Enterprise (HPE) / AOS-CX≤ 10.17.0001 · ≤ 10.16.1020 · ≤ 10.13.1160 · ≤ 10.10.1170
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences