CVE-2026-23601
MEDIUM EPSS 0.4%
Published Mar 4, 20263mo ago · Modified Jun 17, 20262w ago
5.4 CVSS 3.1
Published Mar 4, 2026 3mo ago
Last Modified Jun 17, 2026 2w ago
Description
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector Adjacent
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
0.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-327
Affected Products 23
| Vendor | Product | Version | Range |
|---|---|---|---|
| arubanetworks | arubaos | * | ≥6.5.4.0 – ≤8.10.0.21 |
| arubanetworks | arubaos | * | ≥8.11.0.0 – ≤8.12.0.6 |
| arubanetworks | arubaos | * | ≥8.13.0.0 – ≤8.13.1.1 |
| arubanetworks | arubaos | * | ≥10.3.0.0 – ≤10.4.1.10 |
| arubanetworks | arubaos | * | ≥10.5.0.0 – ≤10.7.2.2 |
| arubanetworks | arubaos | 10.8.0.0 | any |
| arubanetworks | 7010 | * | any |
| arubanetworks | 7030 | * | any |
| arubanetworks | 7205 | * | any |
| arubanetworks | 7210 | * | any |
| arubanetworks | 7220 | * | any |
| arubanetworks | 7240xm | * | any |
| arubanetworks | 7280 | * | any |
| arubanetworks | 9004 | * | any |
| arubanetworks | 9004-lte | * | any |
| arubanetworks | 9012 | * | any |
| arubanetworks | 9106 | * | any |
| arubanetworks | 9114 | * | any |
| arubanetworks | 9240 | * | any |
| arubanetworks | ap-634 | * | any |
| arubanetworks | ap-635 | * | any |
| arubanetworks | ap-654 | * | any |
| arubanetworks | ap-655 | * | any |
References 1
- support.hpe.com https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.