Impact
The vulnerability is an authenticated path traversal flaw in HPE AOS‑CX that lets an attacker copy arbitrary files to a directory that the operating system’s command‑line interface can read. By controlling the contents and destination of the copied file, the attacker can later execute code on the host, thus gaining remote execution privileges.
Affected Systems
Only Hewlett Packard Enterprise’s AOS‑CX platform is affected. No specific affected versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % suggests that exploitation attempts are presently unlikely. The flaw requires authenticated access to the operating system’s CLI, so a compromised or privileged account would be needed; an attacker would issue a crafted command that abuses the path traversal to place a malicious file in a publicly accessible directory and then trigger its execution. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment