Impact
A flaw in the Credential Manager permits an unauthenticated remote attacker to exploit a predictable factory-default password. The vulnerability allows the attacker to bypass authentication entirely and gain full administrative control during the initial setup of the device. This reflects a hard‑coded or default password weakness (CWE-521) and also represents a weakness in password handling and storage.
Affected Systems
The issue affects Hewlett Packard Enterprise AOS-CX devices that remain in their factory-default or post‑Zero‑Touch‑Provisioning state before an administrator has set unique credentials. No specific version information is supplied, so all such devices are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. While the EPSS score is less than 1%, the exploitation route is straightforward: an unauthenticated attacker can access the device over the network during the early setup window. The weakness is exploitable remotely without prior authentication and grants full control, underscoring the urgency for remediation. The flaw involves a hard‑coded default password and an insufficient password protection mechanism (CWE-521).
OpenCVE Enrichment