Impact
A command injection flaw in the web‑based management interface of AOS‑8 and AOS‑10 allows an attacker who is already authenticated to upload arbitrary files to the underlying operating system, which could lead to execution of those files with privileged rights.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s Aruba Networking Wireless Operating System (AOS) versions 8 and 10.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires remote authenticated access to the web interface; therefore, the attack vector is a remote network‑based, authenticated vector. Given its high severity and the need for valid credentials, the risk is significant for systems that expose the management interface to untrusted networks or have weak access controls.
OpenCVE Enrichment