Impact
A business logic flaw in the API of HPE Networking Fabric Composer grants an authenticated low‑privilege operator the ability to gain higher privileges and alter settings beyond their authorized level, effectively enabling privilege escalation. This weakness allows the attacker to perform actions normally restricted by role‑based controls, potentially exposing sensitive information and corrupting system configuration. The vulnerability aligns with CWE‑269 – Improper Privilege Management.
Affected Systems
The affected vendor is Hewlett Packard Enterprise, specifically the Fabric Composer product. No detailed version information was provided, so the full scope of impacted releases cannot be determined from the available data.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability, but the EPSS score is not provided and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation activity. Attackers would need authenticated access to the system, typically from an internal network or compromised administrator account. The real‑world impact therefore depends on the network segmentation and role configuration of the target environment.
OpenCVE Enrichment