Impact
A flaw in the web‑based management interface of an AOS‑10 Gateway allows an authenticated remote attacker to request arbitrary files from the device’s underlying operating system. Once exploited, the attacker can download sensitive system files, exposing confidential information that may be used for further attacks. The vulnerability is an example of improper access control with potential to compromise confidentiality.
Affected Systems
Hewlett Packard Enterprise Aruba Networking Wireless Operating System (AOS) version 10, specifically the AOS‑10 Gateway devices. No specific firmware or build numbers are listed.
Risk and Exploitability
The CVSS score of 4.9 classifies the vulnerability as moderate. The EPSS score is not available, and the issue is not listed in CISA KEV, indicating no known widespread exploitation. The attack vector is remote via the web interface, and the vulnerability requires the attacker to be authenticated. No further details on the type of authentication or privileged level are provided in the description.
OpenCVE Enrichment