Impact
A signature verification bypass flaw has been identified in the command line interface of HPE AOS‑CX. The flaw enables an authenticated malicious actor who holds administrative privileges to run arbitrary code on the operating system when certain pre‑conditions outside of the attacker’s control are satisfied. The impact is direct compromise of the underlying operating system, offering full code execution capabilities to the attacker. This is a serious credential‑based vulnerability with potential for significant confidentiality, integrity, and availability damage.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise AOS‑CX products. No specific product versions are listed in the advisory, so all deployed installations need to be verified against the vendor’s documentation. Administrators should check that the CLI components are up‑to‑date and assess whether their environment can satisfy the pre‑conditions required for exploitation.
Risk and Exploitability
With a CVSS score of 7.9 the vulnerability is considered high severity. Its EPSS score of < 1% indicates a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. The flaw requires authenticated administrative access, so only privileged users with CLI capability could exploit it. The attack vector is inferred to be through the command line, where a malicious user could supply specially crafted input that bypasses signature checks. Because the exploit is credential‑based and requires specific pre‑conditions, risk is elevated primarily in environments where administrative CLI access is exposed or not strictly controlled.
OpenCVE Enrichment