Impact
A vulnerability in the web‑based management interface of HPE AOS‑CX allows an authenticated remote attacker to perform a server‑side request forgery. By leveraging this flaw the attacker can instruct the target system to access arbitrary URLs, enabling enumeration of internal network resources and leaking of sensitive configuration details. The attack does not grant unrestricted control but may allow limited modification of sensitive information. The flaw belongs to the Server‑Side Request Forgery weakness (CWE‑918) and can lead to information exposure (CWE‑200).
Affected Systems
The affected product is Hewlett Packard Enterprise AOS‑CX. No specific version range was cited in the advisory, so all releases that include the web‑based management interface remain potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no known active exploitation at present. However, because the vulnerability requires authentication to the web interface, only users who have legitimate administrative credentials can exploit it; an attacker must first compromise an account or gain fraudulent access. Once authenticated, the SSRF can be triggered without additional privileges, and the attacker can enumerate internal hosts or fetch sensitive data. The risk therefore is moderate, with exploitation depending on credential compromise.
OpenCVE Enrichment