Description
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
Product status
10.7.0.0
10.4.0.0
8.13.0.0
8.12.0.0
8.10.0.0
Credits
zzcentury from Ubisectech Sirius Team
References
support.hpe.com/...y?docId=hpesbnw04957en_us&docLocale=en_US