CVE-2026-23811
LOW EPSS 5.0%
Published Mar 4, 20263mo ago · Modified Jun 17, 20261w ago
3.1 CVSS 3.1
Published Mar 4, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a port-stealing attack - may enable a bi-directional Machine-in-the-Middle (MitM) attack.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector Adjacent
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
5.0% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-300
Affected Products 23
| Vendor | Product | Version | Range |
|---|---|---|---|
| arubanetworks | arubaos | * | ≥6.5.4.0 – ≤8.10.0.21 |
| arubanetworks | arubaos | * | ≥8.11.0.0 – ≤8.12.0.6 |
| arubanetworks | arubaos | * | ≥8.13.0.0 – ≤8.13.1.1 |
| arubanetworks | arubaos | * | ≥10.3.0.0 – ≤10.4.1.10 |
| arubanetworks | arubaos | * | ≥10.5.0.0 – ≤10.7.2.2 |
| arubanetworks | arubaos | 10.8.0.0 | any |
| arubanetworks | 7010 | * | any |
| arubanetworks | 7030 | * | any |
| arubanetworks | 7205 | * | any |
| arubanetworks | 7210 | * | any |
| arubanetworks | 7220 | * | any |
| arubanetworks | 7240xm | * | any |
| arubanetworks | 7280 | * | any |
| arubanetworks | 9004 | * | any |
| arubanetworks | 9004-lte | * | any |
| arubanetworks | 9012 | * | any |
| arubanetworks | 9106 | * | any |
| arubanetworks | 9114 | * | any |
| arubanetworks | 9240 | * | any |
| arubanetworks | ap-634 | * | any |
| arubanetworks | ap-635 | * | any |
| arubanetworks | ap-654 | * | any |
| arubanetworks | ap-655 | * | any |
References 1
- support.hpe.com https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.