Impact
The vulnerability resides in the operating system of HPE AOS-CX switches and allows an unauthenticated remote actor to bypass existing authentication controls. This flaw can enable the attacker to modify protected resources and disrupt limited services, thereby undermining authorized configuration integrity. The weakness aligns with CWE-287, Improper Authentication.
Affected Systems
HPE AOS-CX switches are affected. No specific firmware versions are listed in the available data, so all deployments of the AOS-CX platform should be considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the issue. The EPSS score is not available, preventing a precise estimate of exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and unauthenticated, whereby an attacker can reach the switch through its management interfaces and exploit the authentication bypass to alter configurations or temporarily interrupt services.
OpenCVE Enrichment