Impact
An authentication vulnerability in the management interface and API permits an unauthenticated remote attacker to bypass authentication controls or exhaust system resources. When successfully leveraged, the attacker may gain unauthorized access to the management console or cause denial of service to the interface.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise AOS-CX network devices. No specific product versions are listed in the current data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity of exploitation, while the EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, requiring the attacker to reach the management interface from the network. The conditions for exploitation are acknowledged but not detailed, so an attacker who can reach the interface may attempt to bypass authentication or trigger resource exhaustion.
OpenCVE Enrichment