Description
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
Published: 2026-09-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can exploit the API of HPE Networking Fabric Composer without authentication to cause a denial of service. The vulnerability allows continuous or repeated requests to be sent to the API, exhausting its resources and temporarily disabling the interface used for fabric management. No credentials are required, so any host that can reach the API endpoint is a potential attacker. The result is a loss of availability for the affected fabric controller, which can cascade into broader service outages.

Affected Systems

The flaw is present in HPE Networking Fabric Composer from Hewlett Packard Enterprise. Specific affected versions are not listed, meaning that all deployments of Fabric Composer lacking the vendor’s documented fix are potentially vulnerable. The product is normally deployed in data‑center fabric control planes and accessed through API calls.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. EPSS data is unavailable, so the precise exploitation probability cannot be quantified, but the lack of authentication requirements suggests that an attacker could automate the exploit once network access is achieved. HPE has not included this issue in the CISA KEV catalog, implying no widespread exploitation has been recorded. The attack vector is remote over the API, so any compromised machine or a machine on the same network that can reach the API is enough to launch the attack.

Generated by OpenCVE AI on September 2, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the HPE fix or upgrade Fabric Composer to a version that contains the patch, following the guidance in the referenced HPE support article.
  • Restrict or disable the vulnerable Fabric Composer API endpoints by configuring network access controls or firewall rules so that only trusted hosts can communicate with the API.
  • Continuously monitor Fabric Composer logs for unusually high API request rates and set alert thresholds to detect potential denial‑of‑service attempts.

Generated by OpenCVE AI on September 2, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.
Title Unauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric Composer
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:28.107Z

Reserved: 2026-08-13T16:36:38.746Z

Link: CVE-2026-73715

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T20:17:18.957

Modified: 2026-09-01T21:08:28.570

Link: CVE-2026-73715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T01:30:19Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption