CVE-2026-23824: Unauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling Component
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23824?
The severity of CVE-2026-23824 is rated as high, with a score of 7.5.
How can I fix CVE-2026-23824?
To fix CVE-2026-23824, update to the latest patched version of ArubaOS that addresses the vulnerability.
What types of attacks can be performed using CVE-2026-23824?
An unauthenticated attacker can perform a denial-of-service attack by sending specially crafted network messages to the affected service.
Which systems are affected by CVE-2026-23824?
CVE-2026-23824 affects Arubanetworks ArubaOS versions AOS-8 and AOS-10.
What components are impacted by CVE-2026-23824?
CVE-2026-23824 impacts the protocol-handling component of the affected ArubaOS versions.