Impact
This vulnerability allows an unauthenticated attacker to influence the web interface of the HPE Networking Fabric Composer to redirect a user to an arbitrary URL. The flaw is an open redirect (CWE-601) that could be leveraged to execute phishing attacks or trick users into visiting malicious sites which might lead to credential theft or further exploitation of the victim’s session.
Affected Systems
HPE Networking Fabric Composer is affected. No specific product versions are listed in the disclosure, so all deployments of the Fabric Composer web interface that are not yet patched are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated request via the publicly accessible web interface, allowing an adversary to craft a redirect URL and lure users into visiting malicious destinations.
OpenCVE Enrichment