Impact
An AOS‑CX web‑based management interface contains a missing CSRF protection for sessions authenticated with certificates. Because the interface does not verify that requests originate from the legitimate signed‑in session, an attacker who tricks an authenticated user into visiting a crafted URL can cause the user’s browser to send arbitrary input to endpoints on the interface. The result could be unauthorized configuration changes or potentially the execution of arbitrary commands if those inputs are processed with elevated privileges. This represents a significant security flaw in the integrity and confidentiality of the device’s management plane.
Affected Systems
Vendors: Hewlett Packard Enterprise, product AOS‑CX. The vulnerability applies to all AOS‑CX switches that still rely on the unpatched web interface; specific model or firmware revision numbers are not disclosed, but any device running the current version of the AOS‑CX web console that has certificate‑authenticated sessions is susceptible.
Risk and Exploitability
The CVSS score of 8.3 classifies the issue as High severity. EPSS is not available, so the real‑world exploitation probability is unknown, but the CVE is listed as not in the CISA KEV catalog. An adversary can exploit the flaw remotely without authentication by convincing an already authenticated user to load a malicious web page, so the attack vector is remote and unauthenticated. Because the weakness lies in missing CSRF validation, it does not require privileged network access or additional credentials beyond the user’s authenticated session with the switch.
OpenCVE Enrichment