Impact
The vulnerability arises from improper handling of input in the HPE Networking Fabric Composer API, allowing an attacker who is authenticated to inject SQL statements. This can lead to unauthorized reading, modification, or deletion of data stored in the underlying database, and in severe cases may enable broader compromise of the host running the Fabric Composer software. The weakness is a classic SQL injection flaw, which maps to CWE-89.
Affected Systems
The flaw affects HPE Networking Fabric Composer products deployed by Hewlett Packard Enterprise. No specific version numbers are provided in the advisory, so any installation of Fabric Composer that has not been updated to a patched release should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, with a medium probability of successful exploitation in real-world settings. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploits. Because the vulnerability requires an authenticated user, a threat actor would need valid credentials to abuse the API, but once authenticated, the attacker could inject arbitrary SQL and potentially achieve complete host compromise.
OpenCVE Enrichment