{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-23809","assignerOrgId":"eb103674-0d28-4225-80f8-39fb86215de0","state":"PUBLISHED","assignerShortName":"hpe","dateReserved":"2026-01-16T15:22:38.201Z","datePublished":"2026-03-04T16:10:02.829Z","dateUpdated":"2026-04-01T16:22:10.710Z"},"containers":{"cna":{"providerMetadata":{"orgId":"eb103674-0d28-4225-80f8-39fb86215de0","shortName":"hpe","dateUpdated":"2026-04-01T16:22:10.710Z"},"title":"MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection","affected":[{"vendor":"Hewlett Packard Enterprise (HPE)","product":"HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8)","versions":[{"status":"affected","version":"10.8.0.0","versionType":"semver"},{"status":"affected","version":"10.7.0.0","lessThanOrEqual":"10.7.2.2","versionType":"semver"},{"status":"affected","version":"10.4.0.0","lessThanOrEqual":"10.4.1.10","versionType":"semver"},{"status":"affected","version":"8.13.0.0","lessThanOrEqual":"8.13.1.1","versionType":"semver"},{"status":"affected","version":"8.12.0.0","lessThanOrEqual":"8.12.0.6","versionType":"semver"},{"status":"affected","version":"8.10.0.0","lessThanOrEqual":"8.10.0.21","versionType":"semver"}],"defaultStatus":"affected"}],"descriptions":[{"lang":"en","value":"A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker to redirect and intercept the victim's network traffic, potentially resulting in eavesdropping, session hijacking, or denial of service.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker to redirect and intercept the victim's network traffic, potentially resulting in eavesdropping, session hijacking, or denial of service.</p>"}]}],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05026en_us&docLocale=en_US"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":5.4,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}}],"credits":[{"lang":"en","value":"Xin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian, Zhaowei Tan,Srikanth V. Krishnamurthy from University of California, and Mathy Vanhoef from DistriNet, KU Leuven","type":"finder"}],"source":{"advisory":"HPESBNW05026","discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-400","lang":"en","description":"CWE-400 Uncontrolled Resource Consumption"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-03-04T17:41:07.844389Z","id":"CVE-2026-23809","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-03-04T17:41:44.119Z"}}]}}