Impact
A vulnerability in the underlying operating system of HPE Networking Fabric Composer allows an unauthenticated adjacent attacker to run arbitrary commands on the host, provided that certain preconditions outside the attacker’s control are met. This can lead to full compromise of the underlying operating system, giving the attacker the same privileges as the running service. The weakness can be classified as an OS command injection or improper access control flaw.
Affected Systems
The affected system is Hewlett Packard Enterprise Networking Fabric Composer. No specific operating system or version information is listed, but the bug targets the installation process of the Fabric Composer stack on the underlying host.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is through network communication from an adjacent attacker without requiring authentication, so it is assumed the exploit could be delivered remotely. The issue would allow the attacker to execute arbitrary commands on the host, leading to loss of confidentiality, integrity, and availability.
OpenCVE Enrichment