Impact
A vulnerability in the underlying operating system of HPE Networking Fabric Composer permits an unauthenticated remote attacker to run arbitrary commands as a privileged user on the host, potentially leading to full compromise of the Fabric Composer system. The flaw arises from insufficient validation of external input that can be leveraged to perform operating‑system command injection, a typical code‑execution weakness. Successful exploitation allows the attacker to execute any commands they choose, creating a full administrative foothold on the affected appliance.
Affected Systems
The affected product is HPE Networking Fabric Composer from Hewlett Packard Enterprise. Specific version information is not provided, so all current releases may be impacted until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Nevertheless, because the bug can be triggered without authentication and the underlying RCE is privileged, the risk remains considerable for deployments that are exposed to untrusted networks or lack strong segregation. The likely attack vector is remote, unauthenticated access, requiring the attacker to satisfy certain preconditions that are out of their control but which exist in many Fabric Composer environments.
OpenCVE Enrichment