Impact
The vulnerability permits an authenticated low‑privilege operator to modify the state of specific settings through the HPE Networking Fabric Composer API, effectively elevating their privileges and enabling unauthorized configuration changes. This access control flaw can compromise the integrity and availability of the network environment by allowing altered system states that may lead to misconfiguration, service degradation, or interruption.
Affected Systems
HPE Networking Fabric Composer, a product from Hewlett Packard Enterprise. Version information is not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of '< 1%' reflects a very low probability of exploitation. It is not listed in the CISA KEV catalog. The vulnerability requires the attacker to be authenticated to the API; successful authentication is the prerequisite before the broken access control can be abused. No widespread exploitation has been reported at this time.
OpenCVE Enrichment