Impact
The flaw is an unauthorized privilege escalation in the web‑based interface of HPE Fabric Composer. Authenticated low‑privilege operators can perform state changes that should not be allowed by their current authorization level. This leads to unauthorized configuration changes, violating integrity safeguards. The weakness involves privilege and authorization management (CWE‑269), and certain implementation misconfigurations (CWE‑863). The likely attack vector is an authenticated user accessing the web interface, as the vulnerability requires successful login.
Affected Systems
The vulnerability affects HPE Fabric Composer. No explicit product version information is provided, so any deployment of Fabric Composer should be evaluated against this risk. Consult HPE support for specific version guidance.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity. EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, which implies a currently low exploitation likelihood. Exploitation requires authenticated access to the web interface, limiting risk to accounts that legitimately exist but have lower privilege.
OpenCVE Enrichment