Impact
The vulnerability is a command injection flaw in the web‑based management interface of the AOS‑8 and AOS‑10 operating systems. An attacker who has authenticated access to the interface can upload arbitrary files that are executed by the underlying operating system, allowing them to run code with privileged user rights.
Affected Systems
Hewlett Packard Enterprise’s Aruba Networking Wireless Operating System (AOS), specifically versions AOS‑8 and AOS‑10.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The flaw requires the attacker to first authenticate to the web interface, a condition that typically limits exploitation to users with legitimate or stolen credentials. Once authenticated, the attacker can upload files that are executed with elevated privileges, making the impact severe if credentials are compromised or weakly protected. The lack of public exploit evidence means the likelihood of an active attack is uncertain, but the combination of privilege escalation and the ease of file upload makes it a priority for remediation.
OpenCVE Enrichment