Impact
Authentication required to access the AOS‑CX command line interface allows an attacker who has valid credentials to supply crafted input that is not properly sanitized. This leads to execution of arbitrary shell commands as the privileged OS user, giving the attacker full control over the device and any connected network resources. The weakness corresponds to OS command injection (CWE‑78).
Affected Systems
The affected product is Hewlett Packard Enterprise’s AOS‑CX network operating system. All versions of the CLI are vulnerable; no specific version numbers are disclosed by HPE in the public advisory. Administrators should verify that all installed AOS‑CX images have applied the latest HPE security update once it becomes available.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate‑to‑high severity for a remote authenticated vulnerability. EPSS is not listed, so the current exploitation probability cannot be quantified, but the absence from the CISA KEV catalog does not diminish the need for remediation. Based on the description, the likely attack vector is remote authenticated access to the CLI; an attacker who can log in with a privileged account could inject commands that run with OS‑level permissions.
OpenCVE Enrichment