CVE-2026-44878
Received Received - Intake

ECOS Device Web Interface Filesystem Access Vulnerability

Vulnerability report for CVE-2026-44878, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the web-based management interface of an ECOS device. It allows a highly privileged, authenticated remote attacker to access the device's filesystem. If exploited, an attacker could read sensitive files, modify system data, or delete files.

Impact Analysis

An attacker could gain unauthorized access to sensitive files, alter critical system data, or delete important files. This could disrupt device operations, lead to data breaches, or cause system failures depending on the device's role.

Compliance Impact

This vulnerability could lead to unauthorized access or tampering with sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Non-compliance may result in legal penalties, data breach notifications, and reputational damage.

Mitigation Strategies

Immediately restrict access to the web-based management interface of the ECOS device to trusted networks and users. Ensure only highly privileged and necessary personnel have access. Monitor filesystem access logs for unusual activity and update the device firmware if a patch is available from the vendor.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44878. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart