Description
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.
Product status
10.7.0.0 (semver)
10.4.0.0 (semver)
8.12.0.0 (semver)
8.10.0.0 (semver)
Credits
ZZ from Moonlight Bug Hunter
LIUPENG
References
support.hpe.com/...y?docId=hpesbnw04845en_us&docLocale=en_US