Impact
AOS-S exposes an API that allows authenticated read-only users to gain administrative privileges, which can lead to complete compromise of the switch configuration and any network segment that relies on it, affecting confidentiality, integrity, and availability.
Affected Systems
Hewlett Packard Enterprise’s AOS-S Switches are affected. No specific firmware or software version was identified in the available CNA data, so all deployments running the current API should consider themselves potentially vulnerable until a patch notice is issued.
Risk and Exploitability
The CVSS score of 8.8 categorizes this vulnerability as high severity. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires an authenticated session with the API, suggesting that the attack vector is likely remote over the network, but the attacker must first obtain read-only credentials. Once the flaw is leveraged, elevated privileges allow arbitrary configuration changes and full administrative access.
OpenCVE Enrichment