Impact
A remote attacker can exploit an unsecured API endpoint in HPE Networking Fabric Composer to trigger a denial of service. The vulnerability allows the attacker to send unauthenticated requests that consume resources and cause the system to become unavailable. In addition to disrupting availability, exploitation may enable the attacker to perform limited unauthorized modifications on the underlying operating system, potentially compromising system integrity. The impact therefore spans both availability and a risk of unauthorized control changes.
Affected Systems
Hewlett Packard Enterprise’s Fabric Composer product is affected. No specific firmware or software version ranges are enumerated in the notes, indicating that all versions of Fabric Composer that include the vulnerable API endpoint may be impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity level, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote and unauthenticated, requiring only the ability to reach the affected API endpoint. Successful exploitation does not require local access or privileged credentials, but it can lead to service disruption and potentially unauthorized system modifications, posing a significant risk to operational continuity.
OpenCVE Enrichment