Impact
A remote attacker can craft a malicious value for the esps.apcm.version parameter in the delete API, leading to command injection that allows execution of arbitrary commands on the affected device. The flaw directly impacts the confidentiality, integrity, and availability of the device because it grants the attacker full control over the operating system.
Affected Systems
The flaw exists in H3C NX15 running firmware V100R017. Any instance of this device that exposes the /api/esps delete endpoint is susceptible, and only this version has been documented as vulnerable; earlier or later firmware releases are not known to be affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. Although an EPSS value is not available, the public disclosure means it may be actively exploited. The flaw is not yet listed in CISA’s KEV catalog, but the ability to execute commands remotely gives an attacker full device takeover with no mitigations in place.
OpenCVE Enrichment