Impact
The vulnerability is a local privilege escalation that allows an attacker with local access to execute code as the root user on the host operating system. This full system compromise permits reading, modifying, and deleting any data, installing backdoors, or disrupting services.
Affected Systems
Affected systems include Hewlett Packard Enterprise’s Fabric Composer component in the HPE Networking Fabric Solution. Any installation that has not applied the vendor’s patch is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access, which could be obtained through physical access or compromise of local user credentials. Once executed, the attacker gains root privileges and can fully control the underlying operating system.
OpenCVE Enrichment