Impact
Authenticated path traversal vulnerabilities exist in the API endpoints of Hewlett Packard Enterprise’s AOS‑CX platform. When an attacker with valid credentials accesses these APIs, the flaw allows writing arbitrary files to the underlying operating system. An attacker can place malicious executables or scripts, resulting in remote code execution on the device.
Affected Systems
The affected products are Hewlett Packard Enterprise’s AOS‑CX network devices. All releases of AOS‑CX that have not applied the HPE patch for the path traversal flaw are vulnerable. The issue is present across all API endpoints within the AOS‑CX platform.
Risk and Exploitability
The CVSS score of 7.2 classifies this vulnerability as high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, but the requirement for authenticated access combined with the ability to write arbitrary files indicates a significant risk. Attackers need legitimate credentials or weak authentication to exploit the flaw, which could be feasible on unmanaged or poorly secured devices.
OpenCVE Enrichment