Impact
AOS-CX includes an API endpoint that allows writing arbitrary files to the underlying operating system without requiring authentication. This flaw enables an attacker to create or overwrite files on the host, which can then be executed, leading to full remote code execution. The weakness involves uncontrolled path handling that permits writing files to any location on the system.
Affected Systems
The affected vendor is Hewlett Packard Enterprise and the product is AOS-CX. No specific version numbers are listed in the available data, so all current or previously released builds of AOS-CX are potentially at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity RCE risk. The EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw over the network by making unauthenticated requests to the vulnerable API endpoint, assuming the target is reachable without additional network restrictions.
OpenCVE Enrichment