Impact
The vulnerability is a command injection flaw in the command line interface (CLI) of HPE Aruba OS 8 and 10 accessed via the PAPI protocol. An authenticated attacker can supply arbitrary command strings that are executed by the underlying operating system, enabling remote code execution.
Affected Systems
HPE Aruba Networking Wireless Operating System (AOS) versions AOS‑8 and AOS‑10 are affected. The entry point for the flaw is the CLI service accessed through the PAPI protocol; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, but the EPSS score of less than 1 % suggests a very low likelihood of active exploitation in the wild. The flaw is not included in the CISA KEV catalog. Exploitation requires authenticated remote access to the CLI, i.e., a compromised or stolen credential is a prerequisite. Once access is gained, the attacker can inject commands to be executed with the privileges of the CLI user.
OpenCVE Enrichment