Description
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)8.13.0.0 – 8.13.1.1
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)8.12.0.0 – 8.12.0.6
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)8.10.0.0 – 8.10.0.21
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.8.0.0 – 10.8.0.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.7.0.0 – 10.7.2.2
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking Wireless Operating System (AOS)10.4.0.0 – 10.4.1.10