Header image overlay

HPE Aruba CX switches

Our experts keep you up-to-date on critical cyber threats (CVEs)

Critical vulnerability (CVSS 9.8) in Aruba AOS-CX switches. Find out which versions are affected and what update is needed to secure your network.

HPE Aruba CX switches

With this notification, we inform you about a critical vulnerability within HPE Aruba Networking, specifically on Aruba CX switches. This vulnerability enables unauthorised access and requires urgent action.

What is going on?

Hewlett Packard Enterprise (HPE) has discovered a series of vulnerabilities in Aruba AOS-CX, one of which is critical ‘authentication bypass’. This allows a hacker to bypass existing security controls via the web interface and, in some cases, even reset the admin password, leading to full control of the switch.

Several ‘command injection’ problems have also been confirmed.

Affected software versions

The vulnerabilities affect all AOS-CX installations under the following versions:

  • 10.17.xxxx: 10.17.0001 and below
  • 10.16.xxxx: 10.16.1020 and below
  • 10.13.xxxx: 10.13.1160 and below
  • 10.10.xxxx: 10.10.1170 and below

For more information, visit HPE's website: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us&docLocale=en_US

Take action

An update to the latest firmware released by HPE is necessary. Specifically, you need to upgrade to 10.10.1180, 10.13.1161, 10.16.1030 or 10.17.1001 (or newer), as all earlier versions are vulnerable.

We recommend doing this as soon as possible to prevent unauthorised users from accessing the management interface.

What does VanRoey do?

  • We'll schedule a Managed Services customers do not have to do anything: we have already scanned your environment and updated it where necessary.
  • Have you no Managed contract, but want support in checking, patching or securing your switches? Then contact us via support@vanroey.be.

Can't create tickets? Ask here to get an account. If our Engineer needs to remotely control your PC, he or she will ask you to run this software .

Receive our newsletter including invitations to events & interesting industry news!

Receive alerts from current CVEs and tips to remedy them!

By registering, you agree to our privacy policy.

Two Belgian IT players want join forces in a single integrated IT group for managed IT services under the name Dynamate