Impact
An unauthenticated remote attacker can circumvent the proper authentication controls of the AOS‑S management interface if certain external preconditions are satisfied. By exploiting this flaw the attacker gains unauthorized access to the switch’s management functions. The result is privilege escalation to the level of the switch’s administrative interface, allowing configuration changes, network traffic inspection, or further lateral movement.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s AOS‑S Switch. No specific firmware or software version numbers are listed in the advisory, so all revisions that employ the described management interface are potentially impacted. The flaw resides specifically in the remote management layer of the switch.
Risk and Exploitability
The CVSS base score of 9.8 indicates a critical severity, and the absence of an EPSS score means the exploit probability is currently unknown. Because exploiting the weakness requires an unauthenticated remote attack with no prerequisite user interaction, it is deemed a high‑risk threat vector. Although not listed in CISA’s KEV catalog yet, the vulnerability’s critical score suggests that vendors and customers should address it promptly to prevent potential breaches.
OpenCVE Enrichment