Impact
A remote unauthenticated attacker can intercept traffic between a client and the AOS‑CX management API and retrieve information that was not intended to be exposed. This vulnerability allows the attacker to gain access to sensitive data that may help further compromise the system’s confidentiality. The weakness stems from a lack of authentication and encryption on an exposed API endpoint, making it vulnerable to man‑in‑the‑middle attacks.
Affected Systems
Hewlett Packard Enterprise AOS‑CX is affected. No specific version numbers are provided, so all installations of the product should be evaluated for this exposure.
Risk and Exploitability
The CVSS score of 5.9 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, meaning it has no known active exploit at this time. The most likely attack vector is a remote attacker positioned between the client and the affected system who can intercept and read traffic. Exploitation requires no authentication, but the attacker must be able to observe communication to the vulnerable API endpoint.
OpenCVE Enrichment