Impact
The vulnerability is a command injection flaw in the web-based management interface of HPE Networking Fabric Composer. It allows an unauthenticated attacker to execute arbitrary shell commands on the underlying host if certain preconditions that are external to the attacker are met. Successful exploitation would give the attacker full control of the operating system and lead to a complete system compromise.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. No specific version information is provided, so all deployments of this product should be evaluated for potential exposure.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for potential remote code execution. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, so the likelihood of current exploitation is unknown. Attackers would need unauthenticated access to the web interface and the required environmental conditions must exist. Because the flaw permits execution of arbitrary commands, the impact on confidentiality, integrity, and availability is total if exploited.
OpenCVE Enrichment