Impact
A flaw in the API of Hewlett Packard Enterprise Fabric Composer allows an unauthenticated remote user to retrieve limited system information and to modify the state of certain settings. Successful exploitation could reveal internal services and workflows and permit the attacker to make unauthorized changes that might disrupt normal operation of the affected service.
Affected Systems
Hewlett Packard Enterprise Fabric Composer, with no version details specified in the advisory. The product is a network fabric composition platform used to orchestrate networking infrastructure.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score is not available, and the flaw is not listed in CISA's KEV catalog, but the lack of authentication requirement and remote API exposure mean an attacker can exploit it from an external network. The high CVSS rating and remote nature suggest a significant risk if not addressed promptly.
OpenCVE Enrichment