Impact
An authenticated path traversal flaw in the AOS‑CX web‑based management interface enables an attacker with valid credentials to request files outside the intended directory. By crafting special file paths, the attacker can read arbitrary files on the underlying operating system, potentially exposing sensitive configuration or credential data. The weakness arises from insufficient validation of user‑supplied file paths (CWE‑22) and results in a confidentiality breach (CWE‑200).
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s AOS‑CX platform. No specific version range is noted in the CNA data, so all current and future releases should be evaluated until a patch is available.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. Because this flaw requires authentication, it is not exploitable by anonymous users; however, a legitimate manager account can be abused. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, suggesting that widespread exploitation has not been observed yet. Nonetheless, the potential for reading critical files justifies immediate attention.
OpenCVE Enrichment