Hi Qazik,
The reason is that the SSH user of the CE switch performs AAA before applying for a user interface in the VTY view. In this case, the SSH user is restricted by the ACL in the VTY view. Therefore, the user name and password can be entered. To prevent invalid IP addresses from entering the authentication process, run the ssh server acl xxx command to disable the invalid IP addresses.
I hope it helps!