Impact
AOS‑CX exposes a RESTful API endpoint that allows an authenticated user with an operator role to alter critical configuration settings. This privilege‑escalation flaw permits the operator to change system state beyond intended limits, compromising the integrity of the configuration. The attacker could use legitimate credentials to modify network behavior, security policies, or service availability, potentially facilitating further attacks.
Affected Systems
Vendor Hewlett Packard Enterprise, product AOS‑CX. No specific affected versions are listed in the CNA data. The problem resides in the API layer of the system.
Risk and Exploitability
CVSS base score of 6.5 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is an authenticated API call made by an operator account; the attacker must already possess valid credentials. Once the endpoint is accessed, they can change the state of select settings, thereby escalating privileges and potentially destabilizing the system. Because the flaw is tied to authenticated access, general external exposure is limited, but any compromised operator account becomes a vector for this privilege escalation.
OpenCVE Enrichment