Impact
The vulnerability is an insecure handling of files within the HPE Networking Fabric Composer API. If an authenticated user sends malformed or malicious file requests, the system may act on them with privileged operating‑system rights, allowing the attacker to run arbitrary commands. The flaw directly enables code execution without needing additional privilege escalation beyond the authenticated session.
Affected Systems
Hewlett Packard Enterprise Fabric Composer is affected. No specific version information is provided, so all releases that include the vulnerable API routes are at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and the EPSS score of 0.00646 (approximately 0.646%) suggests a very low but non‑zero probability of exploitation. The lack of inclusion in CISA’s KEV catalog does not reduce the risk of exploitation. The requirement for authentication means the adversary must compromise or insert a legitimate user account, after which the attacker can leverage the API to perform file operations that lead to execution of arbitrary code. The likely attack vector is an authenticated remote attacker submitting specially crafted file manipulation requests to the API endpoints.
OpenCVE Enrichment