Impact
An unauthenticated remote code execution flaw exists in the underlying operating system of HPE Networking Fabric Composer. The vulnerability can be triggered only when certain preconditions outside the attacker’s control are satisfied. If an attacker succeeds, they can run arbitrary code with privileged operating‑system rights, resulting in a full compromise of the Fabric Composer host and all data and services running on it. The CVSS base score of 9 indicates a critical impact to confidentiality, integrity, and availability.
Affected Systems
The affected systems are HPE Networking Fabric Composer devices. No specific version information was provided, so all current and future releases must be considered potentially vulnerable until an official patch is applied.
Risk and Exploitability
Because the vulnerability is remote and unauthenticated, an attacker can target the device from outside without needing any credentials. The EPSS score is unavailable, but the high CVSS rating signals a serious risk. The flaw is not yet listed in the CISA KEV catalog, which suggests there are no confirmed widespread exploit incidents at the time of this analysis. However, the potential for complete system takeover warrants a high priority response. The exact attack vector requires that the preconditions be met, but once met, exploitation can occur via normal network traffic handled by the Fabric Composer’s operating system.
OpenCVE Enrichment