Impact
A vulnerability in the web‑based management interface of AOS‑CX allows an authenticated remote attacker to store malicious JavaScript that is later delivered to an administrative user. When the victim views the affected page, the injected script executes in the victim’s browser with the privileges of the interface, permitting arbitrary script execution such as session hijacking, credential theft or further exploitation of the system.
Affected Systems
The affected product is Hewlett Packard Enterprise’s AOS‑CX web‑based management interface. No specific firmware or software versions are listed in the entry.
Risk and Exploitability
The vulnerability has a CVSS score of 8.4, indicating a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that no current widespread exploitation has been reported. The attack requires valid credentials; once authenticated, an attacker can trivially deliver and exercise the stored script, making the exploitation path straightforward for privileged users.
OpenCVE Enrichment