5G Core Breach: Critical HPE Aruba Flaw Allows Unauthenticated Admin Takeover
ID: 90e61447-d9c2-5d92-8f13-84223368169e
STIX ID: report--90e61447-d9c2-5d92-8f13-84223368169e
Feed Name: securityonline.info
Threat Score
HPE Aruba Networking disclosed critical vulnerabilities in its Private 5G Core (v1.24.3.x) — notably CVE-2026-23595, an authentication bypass (CVSS 8.8) that enables unauthenticated creation of admin accounts — along with a management-API service restart (DoS) and two information-leak bugs; administrators are urged to upgrade to v1.25.1.0 immediately to mitigate unauthorized access, service disruption, and data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
