Impact
Privilege escalation vulnerabilities exist in the API of HPE Networking Fabric Composer. A successful attack allows an authenticated low‑privilege operator to alter the state of specific configuration settings that should be restricted to higher‑privilege users. This can expand the attacker’s control within the system, potentially enabling further compromises such as privilege elevation, service disruption, or unauthorized network changes. The weakness arises from inadequate enforcement of access controls that fails to limit state‑changing operations to authorized roles.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. No particular version information is supplied, so any installation that exposes the vulnerable API is at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is reported as less than 1 %, suggesting a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires only authenticated access by a low‑privilege operator, the likelihood of exploitation is relatively high in environments where such users have API access. An attacker can potentially exploit the API directly, bypassing authorization checks, and modify configuration values that should be restricted, thereby escalating privileges within the system.
OpenCVE Enrichment