Impact
The affected product is the HPE Networking Fabric Composer web interface. The vulnerability allows an unauthenticated remote attacker to trick an authenticated user into visiting a crafted URL, leading to retrieval of sensitive configuration or system data. The disclosure can provide information that might help the attacker expand their foothold into other network services. This weakness corresponds to a cross‑site request forgery flaw (CWE‑352).
Affected Systems
Hewlett Packard Enterprise (HPE): Fabric Composer. The specific affected versions are not listed, so all currently deployed versions are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, and the EPSS score of < 1% indicates a very low exploitation probability. The CVE is not listed in the CISA KEV catalog. Because the attack requires the attacker to persuade an authenticated user to click a crafted URL, the risk is primarily social‑engineering based. Once the user interacts, the attacker can read sensitive data that may be used to move laterally within the network.
OpenCVE Enrichment