Impact
The vulnerability is a reflected cross‑site scripting flaw in the web‑based management interface of HPE Networking Fabric Composer. An attacker can embed malicious JavaScript in a request that is reflected back to a victim’s browser. When a user views the crafted page, the browser executes the injected code in the context of Fabric Composer, allowing the attacker to steal session cookies, credentials, or perform other malicious actions on behalf of the user.
Affected Systems
The affected vendor is Hewlett Packard Enterprise, product Fabric Composer. The advisory does not specify firmware or component versions, so all installations of Fabric Composer that expose the web interface remain vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.1 signals a medium severity. Exploitation requires no authentication and proceeds over the network via the unstable web endpoint, making it easier for an attacker with any access to the management interface to launch the attack. No EPSS score is available and the vulnerability is not listed in CISA KEV, but the lack of public exploitation does not reduce its risk. Based on the description, the likely attack vector is a crafted HTTP request that injects script into a reflected response, which is then executed by a victim’s browser while using the interface.
OpenCVE Enrichment