CVE-2026-23601
Published: Mar 4, 2026
Modified: Apr 1, 2026
CVSS v3.1
5.4
Description
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
| Vendor | Product | Versions |
|---|---|---|
Hewlett Packard Enterprise (HPE) | HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8) | affected 10.8.0.0affected 10.7.0.0 - <= 10.7.2.2affected 10.4.0.0 - <= 10.4.1.10affected 8.13.0.0 - <= 8.13.1.1affected 8.12.0.0 - <= 8.12.0.6+1 more versions |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now