Impact
An unauthenticated authentication bypass in the HPE Aruba Networking Private 5G Core application API permits creation of privileged administrative accounts. The flaw is a classic authorization violation (CWE‑284), allowing a remote attacker to gain full administrative control, modify system configurations, and access or alter sensitive data. The resulting impact includes significant confidentiality and integrity compromise and potential availability disruptions if configurations are maliciously altered.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s Aruba Networking Private 5G Core platform. No specific version information is provided, implying that all released releases of the affected product are potentially susceptible until a vendor fix is issued.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1% suggests exploitation probability is currently low but non-zero. The flaw is not yet listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is remote API access; an attacker only needs to reach the application API, for which no authentication is required, to create an administrative user and subsequently control the system.
OpenCVE Enrichment