Impact
AOS-CX command line interface contains an input validation flaw that permits improperly formed inputs to be processed in a way that enables the execution of arbitrary commands with root privileges. Successful exploitation results in local privilege escalation, allowing the attacker to fully compromise the affected device.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise AOS‑CX systems. The published data does not specify a particular version range, so all devices running the default CLI without the vendor’s update are potentially vulnerable. Administrators should inventory their AOS‑CX deployments and confirm whether they have applied any released fixes.
Risk and Exploitability
The CVSS score of 7.3 indicates medium–high severity. With no EPSS provided and the vulnerability not listed in the CISA KEV catalog, public exploitation remains uncertain, but the flaw can be leveraged by an attacker with local access to the CLI. The attack vector is local; an attacker who can authenticate or otherwise access the command line can trigger arbitrary command execution.
OpenCVE Enrichment