Impact
An authentication bypass exists in the underlying operating system of HPE Networking Fabric Composer. An attacker who is present on an adjacent network segment can exploit this flaw without providing credentials and gain the ability to execute arbitrary code as a privileged operating‑system user. This effectively results in a full compromise of the AFC host, allowing the attacker to control the device, modify configurations, or pivot to other systems on the network.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise's Fabric Composer product. No specific firmware or operating‑system versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity. The exploit requires only adjacency on the network, no authentication, and grants execution of arbitrary code with elevated privileges. There is no EPSS value and the vulnerability is not currently listed in CISA's KEV catalog, but the high CVSS and lack of authentication barrier suggest a realistic threat for exposed or poorly segmented environments.
OpenCVE Enrichment