Impact
Command injection vulnerabilities exist in the web‑based management interface of HPE Fabric Composer. An attacker who has authenticated to the interface can insert arbitrary operating‑system commands, which are then executed with the privileges of the web service. This enables the attacker to read, modify, or delete data, install malware, or disrupt services, thereby compromising confidentiality, integrity, and availability of the fabric environment.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. The advisory does not specify affected software versions or build numbers; therefore the vulnerability is likely present in all released versions of the device’s web‑based management interface that have not yet been patched.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high risk, while the EPSS score is < 1%, leaving the likelihood of exploitation uncertain. The vulnerability is not listed in CISA’s KEV catalog, which suggests no widespread exploitation has been reported. The attack requires a valid authenticated session to the management interface; once authenticated, the attacker can execute arbitrary system commands. This combination of authentication requirement and remote execution grants powerful capabilities to an attacker who can compromise credentials or use a privileged account.
OpenCVE Enrichment