Impact
The vulnerability in the HPE Networking Fabric Composer API lets an authenticated low‑privilege operator read data that exceeds the permissions originally granted to that user. Exploitation is successful when the attacker uses legitimate API calls, resulting in exposure of sensitive information that can be leveraged for further access to network services supported by Fabric Composer. The CVSS score of 6.5 indicates a moderate severity impact on confidentiality and potentially on the attacker's ability to gain additional footholds.
Affected Systems
The affected product is Hewlett Packard Enterprise’s Fabric Composer. No specific version range is supplied in the CNA data, so all deployed instances of Fabric Composer that expose the vulnerable API may be impacted unless the vendor confirms otherwise.
Risk and Exploitability
The risk is moderate, as reflected by a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to be authenticated with a low‑privilege operator account and to interact with the vulnerable API, making the attack vector an authenticated internal privilege‑misuse scenario rather than a remote unauthenticated one.
OpenCVE Enrichment