Impact
An authenticated user may create or modify arbitrary files on the AOS‑CX appliance, exploiting a weakness identified as CWE‑73 (Relative Path Traversal). By manipulating file paths, the attacker can cause the system to write unintended files or execute arbitrary commands with privileged operating‑system rights. Successful exploitation enables full control of the device, allowing modification of configurations, binaries, or other critical system files and execution of malicious code. The vulnerability requires that the attacker be authenticated, that certain conditions be met outside the attacker’s control, and that a separate user perform a required action, which limits the immediacy of the exploit but does not prevent it when those prerequisites exist.
Affected Systems
Hewlett Packard Enterprise AOS‑CX appliances are affected. No specific product version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. The EPSS score is less than 1%, suggesting that exploits are unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. Because the attack requires legitimate authentication and an additional user action, the window for exploitation is narrow; however, when the conditions are satisfied, the impact is total compromise of the device.
OpenCVE Enrichment