CVE-2026-44879
Awaiting Analysis Awaiting Analysis - Queue

Command Injection in ECOS CLI

Vulnerability report for CVE-2026-44879, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-23

Assigner: Hewlett Packard Enterprise (HPE)

Description

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-23
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hpe ecos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a highly privileged remote attacker to execute arbitrary commands on ECOS devices through command injection in the CLI. It requires authentication but can be exploited remotely.

Detection Guidance

Detection requires checking ECOS devices for vulnerable CLI commands. Review command logs for unusual activity, especially commands executed by privileged users. Inspect network traffic for unauthorized remote access attempts to CLI interfaces.

Impact Analysis

An attacker could gain full control over the affected device, leading to data theft, system compromise, or disruption of services. This could impact confidentiality, integrity, and availability of the system.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements in GDPR and HIPAA. Organizations may face compliance penalties due to potential data breaches.

Mitigation Strategies

Immediately restrict remote access to ECOS devices CLI to trusted networks and users. Disable or remove unnecessary CLI commands that may be vulnerable. Apply vendor patches or updates if available. Monitor network traffic for unusual command injection attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44879. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart