Impact
The vulnerability permits a logged‑in low‑privilege operator to gain administrative rights through the Fabric Composer API. As a result, the attacker can launch commands, alter configurations, and fully compromise the fabric network. This flaw falls under improper access control and can be exploited after authentication, providing broad system control to the attacker.
Affected Systems
Affected are HPE Fabric Composer deployments. The specific affected versions are not listed in the advisory, so all releases before the patch should be considered vulnerable.
Risk and Exploitability
With a CVSS score of 8.8, the flaw is classified as high severity. EPSS score indicates a very low exploitation probability (< 1%), and the vulnerability is not in the CISA KEV catalog, suggesting that exploitation is not yet widespread. However, because the attack vector requires prior authentication, organizations must assume that privileged users can potentially abuse the API if not patched or protected. An attacker could likely exploit this by calling privileged API endpoints with elevated permissions.
OpenCVE Enrichment