Impact
The vulnerability is an authorization bypass in the API endpoint of HPE AOS‑CX that permits a remote actor to circumvent existing access controls. This flaw allows access to management functionality that should be restricted by the configured policy, potentially compromising the confidentiality, integrity, or availability of system management capabilities. The weakness is an improper authorization flaw, consistent with common access control violations.
Affected Systems
The affected product is Hewlett Packard Enterprise’s AOS‑CX. No specific affected versions are provided in the CVE metadata, so all installed instances should be considered potentially vulnerable until further information is obtained. Check the HPE support reference for any version guidance.
Risk and Exploitability
The CVSS score of 6.6 indicates a medium severity vulnerability, and an EPSS score is not available, so the exact likelihood of exploitation cannot be quantified. The vulnerability remains unnoted in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending crafted requests to the API endpoint, bypassing authorization checks without local privileges. The risk is that unauthenticated or low‑privileged actors could gain elevated management access if the API is exposed to untrusted networks.
OpenCVE Enrichment