An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 |
Wed, 15 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Jan 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files. | |
Title | Authenticated Remote Code Execution in AOS Web-based Management Interface | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: hpe
Published: 2025-01-14T17:35:25.108Z
Updated: 2025-01-23T21:18:23.255Z
Reserved: 2025-01-10T16:27:25.924Z
Link: CVE-2025-23051

Updated: 2025-01-15T15:00:55.216Z

Status : Awaiting Analysis
Published: 2025-01-14T18:16:05.813
Modified: 2025-01-23T22:15:16.000
Link: CVE-2025-23051

No data.