Skip to content
VulniPulse

HPE Aruba Networking AOS-CX Switches Vulnerabilities & Security Advisories

15 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-CX Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 6 high, 7 medium, 1 low.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-CX Switches advisories

High7.2Aruba

High [CVE-2026-63454] AOS-CX: authenticated path traversal vulnerability exists in AOS-CX

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

CVE-2026-63454
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
High7.2Aruba

High [CVE-2026-63453] AOS-CX: Buffer overflow vulnerabilities exist in the command line interface of AOS-CX

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-63453
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
High8.8Aruba

High [CVE-2026-44880] AOS-CX: buffer overflow vulnerability was found in the command line interface of AOS-CX

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

CVE-2026-44880
AOS-CXSwitches (AOS-CX)
Jul 21, 2026
Critical9.8Aruba

Critical [CVE-2026-23813] vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

CVE-2026-23813
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.2Aruba

High [CVE-2026-23816] vulnerability in the command line interface of AOS-CX Switches could

A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-23816
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High7.2Aruba

High [CVE-2026-23815] vulnerability in a custom binary used in AOS-CX Switches' CLI could

A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

CVE-2026-23815
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
High8.8Aruba

High [CVE-2026-23814] vulnerability in the command parameters of a certain AOS-CX CLI command could

A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.

CVE-2026-23814
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
Medium6.5Aruba

Medium [CVE-2026-23817] vulnerability in the web-based management interface of AOS-CX Switches could

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

CVE-2026-23817
AOS-CXSwitches (AOS-CX)
Mar 11, 2026
Medium5.8Aruba

Medium [CVE-2025-37159] vulnerability in the web management interface of the AOS-CX OS user authentication service could

A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.

CVE-2025-37159
Switches (AOS-CX)
Nov 18, 2025
Medium6.7Aruba

Medium [CVE-2025-37158] AOS-CX: command injection vulnerability exists in the AOS-CX Operating System.

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

CVE-2025-37158
Switches (AOS-CX)
Nov 18, 2025
Medium6.8Aruba

Medium [CVE-2025-37156] ArubaOS-CX: platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software.

A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.

CVE-2025-37156
Switches (AOS-CX)
Nov 18, 2025
Medium6.0Aruba

Medium [CVE-2025-27080] Vulnerabilities in the command line interface of AOS-CX could

Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to lateral movement involving those services.

CVE-2025-27080
Switches (AOS-CX)
Mar 18, 2025
Medium4.3Aruba

Medium [CVE-2025-25042] vulnerability in the AOS-CX REST interface could

A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.

CVE-2025-25042
Switches (AOS-CX)
Mar 18, 2025
Low3.3Aruba

Low [CVE-2025-25040] vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300…

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx: All patches - AOS-CX 10.15.xxxx: 10.15.1000 and below The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.

CVE-2025-25040
Switches (AOS-CX)
Mar 18, 2025
Medium4.9Aruba

Medium [CVE-2024-26303] ArubaOS-Switch: Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

CVE-2024-26303
Switches (AOS-CX)
Mar 26, 2024

← All Aruba advisories