Impact
A flaw in the API of Hewlett Packard Enterprise Fabric Composer allows an unauthenticated remote user to retrieve limited system information and to modify the state of certain settings. Successful exploitation could reveal internal services and workflows and permit the attacker to make unauthorized changes that might disrupt normal operation of the affected service, exposing the system to both information disclosure and integrity compromise.
Affected Systems
Hewlett Packard Enterprise Fabric Composer, a network fabric composition platform used to orchestrate networking infrastructure. No specific product versions are enumerated in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score of < 1% shows a very low probability of active exploitation today, and the flaw is not listed in CISA's KEV catalog. Because the API endpoints that allow configuration changes lack authentication, an adversary who can reach the Fabric Composer from an external network can gain limited system insight and alter configuration settings without credentials. This makes it a significant risk for systems whose API is exposed to the internet or an untrusted network.
OpenCVE Enrichment