Impact
A flaw in the HPE Networking Fabric Composer API permits an unauthenticated attacker to execute arbitrary commands on the underlying host, provided that conditions beyond the attacker’s control exist. This remote code execution vulnerability can lead to complete system compromise, including unauthorized data access, modification, or deletion, and can serve as a pivot for further attacks within the network.
Affected Systems
The vulnerability affects the Hewlett Packard Enterprise Fabric Composer product. No specific affected version information is supplied in the advisory, so all installations of Fabric Composer should be verified for the presence of the issued fix.
Risk and Exploitability
The CVSS base score is 8.1, indicating a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as network-based exposure to the Composer API, and the preconditions required lie outside the attacker’s control, meaning exploitation may be limited to environments where the API is publicly exposed and the underlying host’s configuration allows command execution.
OpenCVE Enrichment