PT-2026-67864 · H3C · Nx15
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C NX15 version V100R017
Description
A remote command injection issue exists in the
/api/esps endpoint. The flaw is located within the reload.reload config() function, allowing a remote attacker to execute arbitrary commands on the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
/api/esps endpoint or disable the reload.reload config() function to minimize the risk of exploitation.Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nx15