CVE-2026-23817

A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*

History

13 May 2026, 20:45

Type Values Removed Values Added
CPE cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
First Time Hpe
Hpe arubaos-cx
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us&docLocale=en_US - Vendor Advisory

11 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-601

11 Mar 2026, 13:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la interfaz de gestión basada en web de los switches AOS-CX podría permitir a un atacante remoto no autenticado redirigir a los usuarios a una URL arbitraria.

11 Mar 2026, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 04:17

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23817

Mitre link : CVE-2026-23817

CVE.ORG link : CVE-2026-23817


JSON object : View

Products Affected

hpe

  • arubaos-cx
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')