Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AOS-CX auth bypass and command injection: are your controls enough?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Critical flaws in HPE Aruba Networking AOS-CX can let a remote attacker bypass authentication in the web management interface or inject commands through the CLI, creating a realistic path to administrative control of campus and data center switches, according to CYCOGNITO. The issue is not just patching; exposed management planes and weak access boundaries turn network infrastructure into a privileged foothold.

NHIMG editorial — based on content published by CYCOGNITO: What is CVE-2026-23813 / CVE-2026-23814?

By the numbers:

  • When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.

Questions worth separating out

Q: What breaks when switch management interfaces are exposed to untrusted networks?

A: When management interfaces are reachable beyond a tightly controlled admin zone, attackers can turn configuration services into an initial access path.

Q: Why do authentication bypass flaws in network equipment create disproportionate risk?

A: Network equipment sits in the traffic path and often governs visibility, segmentation, and reachability for the rest of the environment.

Q: How do security teams know if server management-plane controls are actually working?

A: They should be able to show that every controller is inventoried, uniquely authenticated, unreachable from untrusted networks, and fully logged.

Practitioner guidance

  • Inventory every reachable management endpoint Map all AOS-CX web and CLI administration paths, including VPN, jump host, partner, and legacy routes, then confirm which ones are actually reachable from untrusted networks.
  • Constrain switch admin access to a dedicated management zone Use strict ACLs and network segmentation so only approved administration hosts can reach management interfaces, and remove any broad internal access that was added for convenience.
  • Disable unnecessary web management services Turn off HTTP or HTTPS management access where it is not operationally required, and prefer the smallest possible administrative surface for each switch estate.

What's in the full analysis

CYCOGNITO's full analysis covers the operational detail this post intentionally leaves for the source:

  • Version-by-version affected branch mapping for AOS-CX deployments.
  • Specific remediation versions for each supported software branch.
  • External exposure scenarios that increase the likelihood of exploitation.
  • Vendor advisory context for organisations running end-of-maintenance releases.

👉 Read CYCOGNITO's analysis of CVE-2026-23813 and CVE-2026-23814 →

AOS-CX auth bypass and command injection: are your controls enough?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18527
 

Authentication bypass on infrastructure management surfaces is a standing privilege problem, not just a vulnerability class. When a switch management portal can be reached remotely without proper identity checks, the issue is not limited to one CVE. It exposes the assumption that operational interfaces are naturally protected by network location alone. That assumption no longer holds in segmented, hybrid, or partner-connected environments. Practitioners should treat management-plane exposure as a privilege governance problem.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: Who is accountable when a switch management interface becomes an attack path?

A: Accountability is shared across network engineering, IAM or PAM owners, and security operations because the failure spans reachability, privilege, and detection. The governing frameworks should reflect that shared ownership, with patching alone treated as only one part of the control response.

👉 Read our full editorial: AOS-CX management-plane flaws expose switch admin control risk



   
ReplyQuote
Share: