Impact
The vulnerability is an arbitrary file write exposed through the Fabric Composer API that can be leveraged by a logged‑in operator with low privilege to write files anywhere on the system. By creating malicious files such as executables or scripts, the attacker can then trigger those files to run under the operating system’s context, effectively achieving remote code execution and a full compromise of the device.
Affected Systems
All HPE Networking Fabric Composer deployments where the API is enabled and accessible to operator accounts are affected. The issue is specific to HPE Fabric Composer as identified by Hewlett Packard Enterprise.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw. Because the vulnerability requires authentication, attackers must first compromise or use legitimate operator credentials, which may be limited in scope. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog; however, the ability to obtain remote code execution on a networking device is a critical concern, especially in environments that expose the API externally.
OpenCVE Enrichment