CVE-2026-23601 Details
Description
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
A vulnerability exists in the wireless encryption management of Wi-Fi transmissions on HPE Aruba Networking Wireless Operating Systems AOS-8 and AOS-10. This vulnerability allows a malicious actor to create shared-key authenticated transmissions with targeted payloads, impersonating the identity of a primary BSSID. Exploitation of this vulnerability enables the delivery of altered data to specific endpoints, circumventing standard cryptographic protections.
To address this vulnerability, HPE Aruba Networking advises upgrading to AOS-10.8.x.x versions 10.8.0.1 and above, AOS-10.7.x.x versions 10.7.2.3 and above, AOS-10.4.x.x versions 10.4.1.11 and above, AOS-8.13.x.x versions 8.13.1.2 and above, AOS-8.12.x.x versions 8.12.0.7 and above, and AOS-8.10.x.x versions 8.10.0.22 and above. These updates are available through the HPE Networking Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| arubanetworks arubaos | >= 6.5.4.0, <= 8.10.0.21 >= 8.11.0.0, <= 8.12.0.6 >= 8.13.0.0, <= 8.13.1.1 >= 10.3.0.0, <= 10.4.1.10 >= 10.5.0.0, <= 10.7.2.2 10.8.0.0 |
CPE
Remediation
| |
| arubanetworks 7010 | All versions |
CPE
Remediation
| |
| arubanetworks 7030 | All versions |
CPE
Remediation
| |
| arubanetworks 7205 | All versions |
CPE
Remediation
| |
| arubanetworks 7210 | All versions |
CPE
Remediation
| |
| arubanetworks 7220 | All versions |
CPE
Remediation
| |
| arubanetworks 7240xm | All versions |
CPE
Remediation
| |
| arubanetworks 7280 | All versions |
CPE
Remediation
| |
| arubanetworks 9004 | All versions |
CPE
Remediation
| |
| arubanetworks 9004-lte | All versions |
CPE
Remediation
| |
| arubanetworks 9012 | All versions |
CPE
Remediation
| |
| arubanetworks 9106 | All versions |
CPE
Remediation
| |
| arubanetworks 9114 | All versions |
CPE
Remediation
| |
| arubanetworks 9240 | All versions |
CPE
Remediation
| |
| arubanetworks ap-634 | All versions |
CPE
Remediation
| |
| arubanetworks ap-635 | All versions |
CPE
Remediation
| |
| arubanetworks ap-654 | All versions |
CPE
Remediation
| |
| arubanetworks ap-655 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 4, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2026 | New CVE Received | [email protected] |