{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "A vulnerability in OpenSSH's ObscureKeystrokeTiming feature (introduced in version 9.5) renders its keystroke timing obfuscation ineffective due to a logic error. This may allow attackers to observe keystroke timing patterns despite the feature being enabled by default.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "HPE Aruba Networking ArubaOS-CX Switches\n  - 10.16.1000 and below\n  - 10.15.0005 and below\n  - 10.13.1080 and below\n  - 10.10.1150 and below\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by this vulnerability unless explicitly stated otherwise, and are not covered by this security advisory.\n",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Aruba Networking products and software versions not specifically listed above are not affected by the OpenSSH Keystroke Obfuscation Bypass vulnerability.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "This CVE has been widely discussed in public. Additional details about this vulnerability is available at https://www.freebsd.org/security/advisories/FreeBSD-SA-25:01.openssh.asc. At this time, HPE Aruba Networking is not aware of any publicly available exploitation tools or techniques that specifically target HPE Aruba Networking products.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that access to the SSH port on impacted devices be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.",
        "title": "Workaround"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at:\nhttps://www.hpe.com/support/security-response-policy. For reporting NEW HPE Aruba Networking security issues, email can be sent to hpe-networking-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Aruba Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date of the advisory, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: hpe-networking-sirt@hpe.com - For further details please see https://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Aruba Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "category": "self",
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05062en_us&docLocale=en_US"
      },
      {
        "category": "self",
        "summary": "HPE Aruba Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "category": "self",
        "summary": "HPE Aruba Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "OpenSSH Keystroke Obfuscation Bypass in HPE Aruba Networking ArubaOS-CX Switches.  ",
    "tracking": {
      "current_release_date": "2026-06-02T17:00:00.000Z",
      "generator": {
        "date": "2026-06-02T15:23:18.588Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.2"
        }
      },
      "id": "HPESBNW05062",
      "initial_release_date": "2026-06-02T17:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-06-02T17:00:00.000Z",
          "number": "1",
          "summary": "Initial release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "10.16.1010",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": "AOS-CX 10.16.1010"
                }
              },
              {
                "category": "product_version",
                "name": "10.15.1010",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": "AOS-CX 10.15.1010"
                }
              },
              {
                "category": "product_version",
                "name": "10.13.1090",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": "AOS-CX 10.13.1090"
                }
              },
              {
                "category": "product_version",
                "name": "10.10.1160",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": "AOS-CX 10.10.1160"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=10.16.0000|<=10.16.1000",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": ">=10.16.0000|<=10.16.1000"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=10.15.0000|<=10.15.0005",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": ">=10.15.0000|<=10.15.0005"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=10.13.0000|<=10.13.1080",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": ">=10.13.0000|<=10.13.1080"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=10.10.0000|<=10.10.1150",
                "product": {
                  "name": "HPE Aruba Networking ArubaOS-CX",
                  "product_id": ">=10.10.0000|<=10.10.1150"
                }
              }
            ],
            "category": "product_name",
            "name": "ArubaOS-CX"
          }
        ],
        "category": "vendor",
        "name": "HPE Aruba Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Philippos Giavridis",
            "Jacky Wei En Kung",
            "Daniel Hugenroth ",
            "Alastair Beresford "
          ],
          "organization": "University of Cambridge"
        }
      ],
      "cve": "CVE-2024-39894",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-57",
          "title": "Internal Reference"
        }
      ],
      "product_status": {
        "fixed": [
          "AOS-CX 10.16.1010",
          "AOS-CX 10.15.1010",
          "AOS-CX 10.13.1090",
          "AOS-CX 10.10.1160"
        ],
        "known_affected": [
          ">=10.16.0000|<=10.16.1000",
          ">=10.15.0000|<=10.15.0005",
          ">=10.13.0000|<=10.13.1080",
          ">=10.10.0000|<=10.10.1150"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-02T16:00:00.000Z",
          "details": "HPE Aruba Networking ArubaOS-CX Switches\n  - ArubaOS-CX 10.16.xxxx: 10.16.1010 and above\n  - ArubaOS-CX 10.15.xxxx: 10.15.1010 and above \n  - ArubaOS-CX 10.13.xxxx: 10.13.1090 and above \n  - ArubaOS-CX 10.10.xxxx: 10.10.1160 and above\n\nSoftware versions with resolution/fixes for the Vulnerability covered above can be downloaded \nfrom the HPE Networking Support Portal at https://networkingsupport.hpe.com/home/\n \nHPE Aruba Networking does not evaluate or patch software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking \nEnd of Life policy please visit: https://www.hpe.com/psnow/doc/a00143052enw\n",
          "product_ids": [
            "AOS-CX 10.16.1010",
            "AOS-CX 10.15.1010",
            "AOS-CX 10.13.1090",
            "AOS-CX 10.10.1160"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-06-02T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that access to the SSH port on impacted devices be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above.",
          "product_ids": [
            ">=10.16.0000|<=10.16.1000",
            ">=10.15.0000|<=10.15.0005",
            ">=10.13.0000|<=10.13.1080",
            ">=10.10.0000|<=10.10.1150"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=10.16.0000|<=10.16.1000",
            ">=10.15.0000|<=10.15.0005",
            ">=10.13.0000|<=10.13.1080",
            ">=10.10.0000|<=10.10.1150"
          ]
        }
      ],
      "title": "OpenSSH Keystroke Obfuscation Bypass "
    }
  ]
}