7.2
CVE-2026-23815
- EPSS 0.94%
- Veröffentlicht 11.03.2026 03:12:29
- Zuletzt bearbeitet 22.09.2026 20:02:06
- Erkennungen
Authenticated Command Injection found in AOS-CX Administrative CLI Command
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Arubaos-cx Version < 10.10.1180
Hpe ≫ Arubaos-cx Version >= 10.13.0000 < 10.13.1161
Hpe ≫ Arubaos-cx Version >= 10.16.0000 < 10.16.1030
Hpe ≫ Arubaos-cx Version >= 10.17.0000 < 10.17.1001
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.94% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us&docLocale=en_US