PT-2026-84497 · Aruba · Aos-Cx
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AOS-CX switches (affected versions not specified)
Description
The web-based management interface lacks Cross-Site Request Forgery (CSRF) protection for certain sessions. This allows a remote unauthenticated attacker to execute arbitrary input against the interface by tricking an authenticated user into interacting with a specially crafted URL. CSRF is a technique where an attacker induces a user to perform actions they did not intend to do on a different website.
Recommendations
Restrict access to the web UI immediately.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aos-Cx