Impact
Vulnerabilities in the API endpoint of AOS-CX allow a remote attacker who is authenticated with low privileges to read sensitive information. The flaw permits the retrieval of data that could be leveraged to gain additional access to network services provided by AOS-CX. The weakness in the code relates to improper handling of authentication and authorization for exposed API paths, resulting in unauthorized data exposure. The impact is directly on confidentiality, as attackers can obtain information that should be restricted to higher‑privileged users.
Affected Systems
The vulnerability affects HPE AOS‑CX, a network automation platform from Hewlett Packard Enterprise. No specific product version numbers are supplied in the data, so any instance of AOS‑CX may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity level. The EPSS score is not available, and the vulnerability has not been listed in the CISA KEV catalog, so no public exploitation is recorded at present. The likely attack path requires the attacker to authenticate to the system with low‑privilege credentials, then invoke the vulnerable API endpoint to extract confidential information. Because the vector is remote and only requires legitimate low‑privilege access, the exploit is feasible for attackers who have compromised or legitimately obtained credentials, raising the overall risk for exposed data.
OpenCVE Enrichment