Impact
A command sanitization bypass in the API of HPE Networking Fabric Composer allows an authenticated low-privilege operator user to inject arbitrary operating‑system commands. Successful exploitation can elevate the user’s permissions to administrative level, giving an attacker full control over the device and potentially compromising the wider network. The vulnerability has a CVSS score of 8.8, indicating a high‑severity flaw that can compromise confidentiality, integrity, and availability.
Affected Systems
This flaw affects Hewlett Packard Enterprise's Fabric Composer, the configuration and orchestration tool for its networking fabric. Specific affected versions are not listed in the advisory, so any installation of Fabric Composer should be examined and patched to eliminate the vulnerability.
Risk and Exploitability
The attack vector requires valid credentials to the API and is exploitable over the network by sending crafted requests. The vulnerability is not included in the CISA KEV catalog, and the EPSS score is below 1%, indicating a low probability of widespread exploitation at this time. However, the high CVSS score and the privilege‑escalation nature of the flaw mean that the risk remains significant, necessitating timely mitigation.
OpenCVE Enrichment