There's a bulletin for this now: HPESBNW05081, revised July 28. It covers CVE-2026-35387, an SSH daemon issue in AOS-CX, and lists affected as 10.17.1020 and below, 10.16.1050 and below, 10.13.1170 and below. Fixed in 10.18.0001, 10.17.1021, 10.16.1051, or 10.13.1180. So on 10.17.1001 you're actually below the fix, and you don't need 10.18, 10.17.1021 clears it.
For the person still flagged on 10.17.1021, that's a false positive. The Nessus plugin for OpenSSH under 10.4 says in its own description that it relies only on the self-reported version number and doesn't test the issue. HPE backports fixes without moving the banner, so the version string won't ever satisfy it.
The bulletin also states that any OpenSSH CVE not listed in it doesn't impact AOS-CX. That sentence plus the signed copy from csaf.arubanetworking.hpe.com is what your auditor wants.
------------------------------
Dustin Burns
@Worldcom Exchange, Inc.
If my post was useful accept solution and/or give kudos
------------------------------
Original Message:
Sent: Jul 28, 2026 06:56 AM
From: HR-abaef5
Subject: OpenSSH to be updated to version 10.4 or later, AOS-CX 10.18.xx?
Note that in many cases security fixes are back-ported to earlier releases, which makes just checking the version not always accurate.
If there are new/active CVEs for HPE software, it is expected that the product teams issue a security bulletin. HPE will not publish a vulnerability bulletin if there is found to be no security vulnerability, for example if fixes are backported, or the way a software module is configured/used already mitigates.
More info in the HPE Security Response Policy.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jul 28, 2026 05:27 AM
From: JM-UG7358
Subject: OpenSSH to be updated to version 10.4 or later, AOS-CX 10.18.xx?
I upgraded firmware on Aruba cx6000 model number (R8N89A) went to 10.17.1021 and still get the banner problem. I asked Aruba and they said the CVE is too early for them to confirm if it' already fixed. Also the minor 1021 version for 17 has been updated more recently than the 18 version, going by the last updated date on the Aruba software platform.