Impact
An API in HPE Networking Fabric Composer allows an authenticated administrative user to write files anywhere in the underlying filesystem, potentially overwriting critical system files. By exploiting this flaw the attacker can elevate privileges and execute arbitrary system commands with root privileges, resulting in full remote code execution. The CVSS score of 7.2 indicates moderate to high severity for this capability.
Affected Systems
The vulnerability affects all deployments of Hewlett Packard Enterprise Fabric Composer that expose the administrative API. No specific product version is listed, so any installation of Fabric Composer should be reviewed for this flaw until a confirmed fix is available.
Risk and Exploitability
The risk level is medium to high. Although the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalogue, the ability to write arbitrary files and run system commands at root is a compelling objective for both insiders and attackers who compromise administrative credentials. The likely attack vector is via the privileged API, and the vulnerability can be exploited by an authenticated administrator.
OpenCVE Enrichment