Impact
An authenticated low‑privileged user can inject and execute arbitrary operating‑system commands through vulnerable command‑line operations on a HPE AOS‑CX device. This command‑injection flaw (CWE‑78) also enables arbitrary command execution. By exploiting this vulnerability the attacker can run any OS command as a privileged user, giving full control over the device and the network segment it protects, thereby compromising confidentiality, integrity and availability.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise AOS‑CX devices. No specific version range is supplied in the advisory, so all instances of AOS‑CX that expose the vulnerable command‑line interface are potentially impacted. Administrators should consult HPE documentation to confirm whether their deployment includes the affected operations.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is classified as high severity. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attack requires valid credentials for a low‑privileged account on the device; once authenticated the attacker can execute privileged OS commands via the vulnerable CLI. The lack of a publicly disclosed exploit does not diminish the risk because the flaw itself allows local code execution with elevated privileges.
OpenCVE Enrichment