Impact
A flaw in the base operating system of the HPE Networking Fabric Composer permits an authenticated user with limited privileges, who has local access, to obtain sensitive information. The vulnerability falls under CWE-200 and could enable the attacker to read data that may be used to reach further into the system or other networks.
Affected Systems
The vulnerability affects HPE Networking Fabric Composer. No specific product versions are listed, so all releases without the provided fix are potentially impacted.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity. Because the EPSS score is not available and the issue is not listed in CISA KEV, the likelihood of widespread exploitation is uncertain. The attack vector is local, requiring authentication on the system; an attacker must be able to log into the Composer with a low‑privilege account to leverage the flaw.
OpenCVE Enrichment