An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
Metrics
Affected Vendors & Products
References
History
Wed, 15 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Jan 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files. | |
Title | Authenticated Remote Code Execution in AOS Web-based Management Interface | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: hpe
Published: 2025-01-14T17:35:25.108Z
Updated: 2025-01-15T15:19:33.226Z
Reserved: 2025-01-10T16:27:25.924Z
Link: CVE-2025-23051
Vulnrichment
Updated: 2025-01-15T15:00:55.216Z
NVD
Status : Received
Published: 2025-01-14T18:16:05.813
Modified: 2025-01-14T18:16:05.813
Link: CVE-2025-23051
Redhat
No data.