CVE-2026-23825
CVE-2026-23825: 1 tracked advisory record across Aruba. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Aruba
1 advisory- Advisory severityHigh7.5
High [CVE-2026-23825] AOS-10: Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems
CVE-2026-23825Source published Source updated
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.
- Affected products in this advisory
- AOS-10
- Source-reported affected versions
- AOS-10 10.8.0.0
- AOS-10 10.7.0.0 through 10.7.2.2
- AOS-10 10.4.0.0 through 10.4.1.10
- Source-reported fixed versions
- AOS-10 10.8.0.1 or above
- AOS-10 10.7.2.3 or above
- AOS-10 10.4.1.11 or above
- Mitigation guidance
- Upgrade affected HPE Aruba Networking devices to an applicable fixed release: AOS-10 10.8.0.1 or above, AOS-10 10.7.2.3 or above, AOS-10 10.4.1.11 or above.
- Upgrade Mobility Conductors, Controllers, and Gateways to one of the following AOS-10 or AOS-8 versions (as applicable) to resolve the vulnerabilities described in the details section: - AOS-10.8.x.x: 10.8.0.1 and above; - AOS-10.7.x.x: 10.7.2.3 and above; - AOS-10.4.x.x: 10.4.1.11 and above; - AOS-8.13.x.x: 8.13.1.2 and above; - AOS-8.12.x.x: 8.12.0.7 and above; - AOS-8.10.x.x: 8.10.0.22 and above.
- Workarounds
- To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage.
Android app · Google Play
Monitor future Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.