An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
| Vendor | Product | Versions |
|---|---|---|
| Hewlett Packard Enterprise (HPE) | AOS-CX | 10.17.0000, 10.16.0000, 10.13.0000, 10.18.0000 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | aos-cx | cert_advisory | 90% |
Updated affected versions to specific patch levels (10.13.1180, 10.16.1050, 10.17.1020, 10.18.0), upgraded severity from HIGH to CRITICAL, and adjusted CVSS estimate accordingly.
Initial creation