Impact
A format string vulnerability resides in the command line interface of AOS‑CX. When an attacker supplies specially crafted input, the system interprets the input as a format string, enabling arbitrary code to be executed with the privileges of the operating system user that runs the CLI. Successful exploitation therefore gives an attacker full control over the underlying OS, creating a serious threat to data confidentiality, integrity, and availability.
Affected Systems
Hewlett Packard Enterprise’s AOS‑CX product is impacted. No specific version numbers are listed in the data, implying that all current releases of AOS‑CX could be susceptible until a vendor patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, signalling high severity. EPSS information is absent, so the likelihood of exploitation cannot be quantified from the available data. The flaw is not included in the CISA KEV catalog, indicating no known field‑theft incidents at the time of reporting. The most probable attack vector is remote, where an unauthenticated attacker submits malicious CLI commands over a network connection to trigger the format string error and then executes arbitrary code on the system.
OpenCVE Enrichment