Impact
The vulnerability is a command injection flaw in the web-based management interface of HPE Networking Fabric Composer. It allows an unauthenticated attacker to execute arbitrary shell commands on the underlying host if certain preconditions that are external to the attacker are met. Successful exploitation would give the attacker full control of the operating system and lead to a complete system compromise.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. No specific version information is provided, so all deployments of this product should be evaluated for potential exposure.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity for potential remote code execution. The EPSS score of < 1% suggests that the current likelihood of exploitation is very low, though it does not eliminate risk. This vulnerability is not listed in CISA's KEV catalog. Attackers would need unauthenticated access to the Fabric Composer web interface, and the required environmental conditions must exist. Because the flaw permits execution of arbitrary commands, a successful exploit would give an attacker complete control over the underlying operating system, with total impact on confidentiality, integrity, and availability.
OpenCVE Enrichment