Impact
A remote attacker can exploit the API of HPE Networking Fabric Composer without authentication to cause a denial of service. The vulnerability allows continuous or repeated requests to be sent to the API, exhausting its resources and temporarily disabling the interface used for fabric management. No credentials are required, so any host that can reach the API endpoint is a potential attacker. The result is a loss of availability for the affected fabric controller, which can cascade into broader service outages.
Affected Systems
The flaw is present in HPE Networking Fabric Composer from Hewlett Packard Enterprise. Specific affected versions are not listed, meaning that all deployments of Fabric Composer lacking the vendor’s documented fix are potentially vulnerable. The product is normally deployed in data‑center fabric control planes and accessed through API calls.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS data is unavailable, so the precise exploitation probability cannot be quantified, but the lack of authentication requirements suggests that an attacker could automate the exploit once network access is achieved. HPE has not included this issue in the CISA KEV catalog, implying no widespread exploitation has been recorded. The attack vector is remote over the API, so any compromised machine or a machine on the same network that can reach the API is enough to launch the attack.
OpenCVE Enrichment