Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
affected
8.13.0.0 (semver)
affected
8.12.0.0 (semver)
affected
8.10.0.0 (semver)
affected
10.7.0.0 (semver)
affected
10.8.0.0 (semver)
affected
10.4.0.0 (semver)
affected
Description
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device.
Product status
8.13.0.0 (semver)
8.12.0.0 (semver)
8.10.0.0 (semver)
10.7.0.0 (semver)
10.8.0.0 (semver)
10.4.0.0 (semver)
Credits
zzcentury
References
support.hpe.com/...y?docId=hpesbnw05048en_us&docLocale=en_US