CVE-2026-23812
MEDIUM EPSS 4.3%
Published Mar 4, 20263mo ago · Modified Jun 17, 20262w ago
4.2 CVSS 3.1
Published Mar 4, 2026 3mo ago
Last Modified Jun 17, 2026 2w ago
Description
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for the interception or modification of traffic intended for the legitimate network gateway via a Machine-in-the-Middle (MitM) position.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector Adjacent
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
4.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-300
Affected Products 23
| Vendor | Product | Version | Range |
|---|---|---|---|
| arubanetworks | arubaos | * | ≥6.5.4.0 – ≤8.10.0.21 |
| arubanetworks | arubaos | * | ≥8.11.0.0 – ≤8.12.0.6 |
| arubanetworks | arubaos | * | ≥8.13.0.0 – ≤8.13.1.1 |
| arubanetworks | arubaos | * | ≥10.3.0.0 – ≤10.4.1.10 |
| arubanetworks | arubaos | * | ≥10.5.0.0 – ≤10.7.2.2 |
| arubanetworks | arubaos | 10.8.0.0 | any |
| arubanetworks | 7010 | * | any |
| arubanetworks | 7030 | * | any |
| arubanetworks | 7205 | * | any |
| arubanetworks | 7210 | * | any |
| arubanetworks | 7220 | * | any |
| arubanetworks | 7240xm | * | any |
| arubanetworks | 7280 | * | any |
| arubanetworks | 9004 | * | any |
| arubanetworks | 9004-lte | * | any |
| arubanetworks | 9012 | * | any |
| arubanetworks | 9106 | * | any |
| arubanetworks | 9114 | * | any |
| arubanetworks | 9240 | * | any |
| arubanetworks | ap-634 | * | any |
| arubanetworks | ap-635 | * | any |
| arubanetworks | ap-654 | * | any |
| arubanetworks | ap-655 | * | any |
References 1
- support.hpe.com https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.