Impact
An authenticated low privilege operator with local access to upstream AFC dependencies can exploit a flaw in the operating system of HPE Networking Fabric Composer to view sensitive information that exceeds the operator’s authorized level. This disclosure could provide an attacker with data that may facilitate further unauthorized actions against the system.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise's Fabric Composer product. No specific version numbers are disclosed, so all installations should be evaluated.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity condition. The EPSS score of <1% suggests exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA KEV, implying it has not been reported as a known exploited vulnerability. The likely attack vector requires local authenticated access, so the risk is confined to environments where low‑privilege operators possess local access to upstream dependencies, and no public remote exploitation has been reported.
OpenCVE Enrichment