Impact
A local privilege‑escalation flaw in HPE Networking Fabric Composer permits a legitimate local user or process to gain root privileges and execute arbitrary code on the compromised host. The vulnerability allows the attacker to alter system configuration, exfiltrate data, and gain full control of the machine. The core weakness is a failure to enforce proper access controls, enabling an internal user to bypass authorization checks.
Affected Systems
The vulnerability affects the Hewlett Packard Enterprise Fabric Composer product. Specific release versions are not enumerated in the advisory, so all supported releases of Fabric Composer are considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. The EPSS score of 0.00086 (<1%) indicates a very low exploitation probability. The issue is not listed in the CISA KEV catalog, implying that widespread exploitation has not yet been observed. The attack requires local access, meaning an attacker must already have a foothold on the system; however, once local access is achieved, the flaw enables full root‑level execution.
OpenCVE Enrichment