Impact
The vulnerability arises in the HPE Networking Fabric Composer API. It allows an authenticated low‑privilege operator to read data that exceeds their authorized privilege scope. This can lead to exposure of sensitive configuration or operational data, potentially facilitating further attacks or privilege escalation. The weakness is an improper access control for protected resources (CWE‑284) and data exposure (CWE‑200).
Affected Systems
Hewlett Packard Enterprise Fabric Composer. No specific version ranges were supplied, so all current installations are potentially impacted unless the vendor has released a patch. Users should verify their product version and review the HPE support advisory for any fixed releases.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity with a likely exploitation scenario requiring authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would first authenticate as a low‑privilege operator and then query the API to retrieve unauthorized data, making the exploitation relatively straightforward for a determined attacker with access to the network. The impact is limited to data confidentiality, not to system control or integrity.
OpenCVE Enrichment