Executive brief
A vulnerability exists in the operating systems used by HPE Aruba networking devices, which manage enterprise wireless and wired networks. An attacker can send malicious network traffic to these devices to crash critical system processes. This results in a denial-of-service, potentially disrupting network connectivity and business operations for all connected users.
Technical details
A vulnerability in the protocol-handling component of HPE Aruba AOS-8 and AOS-10 Operating Systems allows for unauthenticated denial-of-service (DoS). The root cause is insufficient input validation (CWE-400) when processing specially crafted network messages. An attacker can exploit this over the network without user interaction or prior authentication. Successful exploitation leads to the termination of a critical system process, causing the affected service or device to become unavailable. The vulnerability is tracked as CVE-2026-23824 with a CVSS v3.1 score of 7.5.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed: Initial disclosure by HPE and NVD publication