HPE Aruba Networking AOS-CX Switches Vulnerabilities & Security Advisories
15 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-CX Switches, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 6 high, 7 medium, 1 low.
Android app · Google Play
Monitor Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
HPE Aruba Networking Security Advisories (PSIRT) via NVD
Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.
Latest Aruba AOS-CX Switches advisories
Medium [CVE-2026-23817] vulnerability in the web-based management interface of AOS-CX Switches could
A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Medium [CVE-2025-37159] vulnerability in the web management interface of the AOS-CX OS user authentication service could
A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of sensitive configuration data.
Medium [CVE-2025-37158] AOS-CX: command injection vulnerability exists in the AOS-CX Operating System.
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
Medium [CVE-2025-37156] ArubaOS-CX: platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software.
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
Medium [CVE-2025-27080] Vulnerabilities in the command line interface of AOS-CX could
Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to lateral movement involving those services.
Medium [CVE-2025-25042] vulnerability in the AOS-CX REST interface could
A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
Medium [CVE-2024-26303] ArubaOS-Switch: Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon
Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon