Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Affected products
Hewlett Packard Enterprise (HPE) · ArubaOS (AOS)