Impact
The vulnerability resides in the Web‑Based Management Interface of HPE Networking Fabric Composer. It permits an unauthenticated adjacent attacker to embed malicious script that is stored and later presented to legitimate users. This stored XSS can allow arbitrary JavaScript execution in the victim’s browser within the context of the affected interface, enabling data theft, session hijacking, or further compromise of the management console.
Affected Systems
Affected products include Hewlett Packard Enterprise Fabric Composer. Precise version information is not specified in the advisory. Administrators should verify that they are running a current release and consult the HPE support site for any published patches.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity flaw. The EPSS score is not available, so the exploitation probability cannot be quantified, but the flaw remains unmitigated in existing deployments. It is not listed in CISA’s KEV catalog. The attack can be carried out by sending malicious input that is stored by the management interface and later served to any authenticated user who views the affected page. Because the attack requires no authentication but relies on an adjacent network presence, the threat remains significant for operators of shared management network segments.
OpenCVE Enrichment