Impact
The vulnerability is a command‑injection flaw exposed through the web‑based management console of HPE AOS‑CX. An authenticated user with low‑privilege accounts can provide crafted input that is passed directly to the operating system, enabling arbitrary command execution. This flaw allows the attacker to run any system commands, potentially gaining full control of the underlying OS, compromising data confidentiality, integrity, and disrupting availability.
Affected Systems
HPE AOS‑CX systems are affected. No specific version numbers are listed in the CNA disclosure, so any installation of the AOS‑CX platform that exposes the web management interface remains vulnerable unless patched or upgraded.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as High severity. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog. The attack vector is remote; it requires authentication to a low‑privileged user account, but once authenticated the attacker can exploit the flaw over the network. Because the flaw permits arbitrary command execution, the impact is potentially very high for affected systems.
OpenCVE Enrichment