High-risk tools in Hpe Networking
48 of the 595 tools in Hpe Networking are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
aos_s_pingExecutePing a destination from an AOS-S switch (async, polls ~60s).
-
aos_s_tracerouteExecuteRun a traceroute from an AOS-S switch (async, polls ~60s).
-
aos8_apply_migration_runExecuteaos8_apply_migration_run
-
aos8_create_migration_runExecuteaos8_create_migration_run
-
aos8_migration_batch_planExecuteaos8_migration_batch_plan
-
aos8_plan_migration_rollbackExecuteaos8_plan_migration_rollback
-
aos8_show_commandExecuteRun a read-only AOS8 `show ...` command through the showcommand API.
-
ap_httpExecuteTest an HTTP GET from an AP's perspective (async, polls ~60s). timeout: 1-10s.
-
ap_httpsExecuteTest an HTTPS GET from an AP's perspective (async, polls ~60s). timeout: 1-10s.
-
ap_nslookupExecuteResolve a hostname from an AP's perspective (async, polls ~60s).
-
ap_pingExecutePing a destination from an AP and return the result (async, polls ~60s).
-
ap_showExecuteRun 'show' commands on an AP (all must start with 'show ', max 20, async polls ~60s).
-
ap_tcpExecuteTest TCP connectivity to host:port from an AP (async, polls ~60s). timeout: 1-10s.
-
ap_tracerouteExecuteRun a traceroute from an AP (async, polls ~60s).
-
apstra_wait_for_taskExecutePoll an Apstra blueprint task until it reaches a terminal state.
-
build_bgp_overlayExecutebuild_bgp_overlay
-
build_ospf_overlayExecutebuild_ospf_overlay
-
build_underlay_ssidExecutebuild_underlay_ssid
-
build_vsf_templateExecutebuild_vsf_template
-
cable_testExecuteRun a cable/TDR test on CX or AOS-S switch ports (async, polls ~60s).
-
clearpass_disconnect_sessionExecuteDisconnect an active ClearPass session via Change of Authorization.
-
cx_pingExecutePing a destination from a CX switch and return the result (async, polls ~60s).
-
cx_showExecuteRun 'show' commands on a CX switch (all must start with 'show ', max 20, async polls ~60s).
-
cx_tracerouteExecuteRun a traceroute from a CX switch (async, polls ~60s).
-
disconnect_clientExecuteForce-disconnect a wireless client by MAC address. ap_serial auto-looked up if omitted.
-
edgeconnect_run_link_integrity_testExecuteStart an EdgeConnect link-integrity iperf/tcpperf test with write guards.
-
execute_config_health_remediationExecuteexecute_config_health_remediation
-
gateway_iperfExecuteRun an iperf throughput test from an Aruba gateway (async, polls ~60s).
-
gateway_ping_sweepExecuteRun a ping sweep (a range of packet sizes) from an Aruba gateway (async, polls ~60s).
-
gateway_showExecuteRun 'show' commands on an Aruba gateway via async troubleshooting API. Each must start with 'show '.
-
invoke_toolExecuteinvoke_tool
-
locate_aos_s_switchExecuteBlink an AOS-S switch's locate LED (POST .../locate).
-
locate_apExecuteBlink an AP's locate LED (POST .../locate). Non-disruptive — no confirmation required.
-
locate_cx_switchExecuteBlink a CX switch's locate LED (POST .../locate).
-
poe_bounceExecutePower-cycle PoE on switch/gateway ports (async, polls ~60s).
-
port_bounceExecuteLink-reset (bounce) switch/gateway ports (async, polls ~60s).
-
reboot_ap_swarmExecuteReboot an entire AP swarm/cluster via one member's serial (POST .../rebootSwarm).
-
reboot_deviceExecuteReboot an AP, CX switch, AOS-S switch, or gateway. device_type auto-detected if omitted.
-
resync_device_configExecuteresync_device_config
-
run_firmware_compliance_campaignExecuterun_firmware_compliance_campaign
-
run_glp_backup_protection_jobExecuterun_glp_backup_protection_job
-
run_speed_testExecuteRun a speed test from an AP to measure uplink bandwidth.
-
run_troubleshooting_bundleExecuterun_troubleshooting_bundle
-
set_firmware_complianceExecuteCreate or update a firmware compliance policy (triggers upgrade).
-
set_glp_virtual_machine_powerExecuteset_glp_virtual_machine_power
-
set_glp_virtual_machines_power_bulkExecuteset_glp_virtual_machines_power_bulk
-
test_aaaExecuteTest AAA connectivity from an AP or CX switch (async, polls ~60s).
-
trigger_device_upgradeExecutetrigger_device_upgrade
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.