Description
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
Product status
10.7.0.0
10.4.0.0
8.13.0.0
8.12.0.0
8.10.0.0
Credits
zzcentury from Ubisectech Sirius Team
References
support.hpe.com/...y?docId=hpesbnw04957en_us&docLocale=en_US