Impact
A remote attacker can craft a malicious value for the esps.apcm.version parameter in the delete API, leading to command injection that allows execution of arbitrary commands on the affected device. The flaw directly impacts the confidentiality, integrity, and availability of the device because it grants the attacker full control over the operating system.
Affected Systems
The flaw exists in H3C NX15 running firmware V100R017. Any instance of this device that exposes the /api/esps delete endpoint is susceptible, and only this version has been documented as vulnerable; earlier or later firmware releases are not known to be affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. An EPSS score of 2% indicates it may be actively exploited, and the public disclosure supports this assessment. The flaw is not yet listed in CISA’s KEV catalog, but the ability to execute commands remotely gives an attacker full device takeover with no mitigations in place.
OpenCVE Enrichment