Impact
Authentication bypass exists in the API of HPE Networking Fabric Composer that allows an authenticated low‑privilege operator to circumvent existing authentication controls. The vulnerability is a classic authentication failure (CWE‑287). Successful exploitation can let an attacker keep limited access to the system even after the legitimate session should have been revoked.
Affected Systems
The affected platform is Hewlett Packard Enterprise Fabric Composer. No specific version information is provided in the data.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The likely attack vector requires an authenticated user with low privileges who can access the API, so the risk is most acute in environments where such operators have broader rights or where API access is not tightly scoped.
OpenCVE Enrichment