Impact
The flaw in the HPE Networking Fabric Composer API permits an authenticated low‑privilege operator to trigger a denial of service. This is a CWE‑400 Uncontrolled Resource Consumption weakness: the system accepts a request that leads to excessive resource usage and service disruption. When successfully exploited, the affected service stops responding, effectively interrupting normal operation for network compositions managed by the application.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. No explicit version information is available, implying that the vulnerability may exist in any release that has not yet been patched by HPE.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is moderately severe. Exploitation requires authentication, but only low‑privilege permissions, which are commonly granted. The EPSS score is not available, and the CVE is not listed in the CISA KEV catalog. The likely attack vector is remote via the API, and successful exploitation can bring the Fabric Composer service to a halt, impacting availability for users relying on it.
OpenCVE Enrichment