Impact
Vulnerabilities in HPE Networking Fabric Composer’s API allow an authenticated low‑privilege operator to read data and perform operations beyond the permissions granted to that role. The flaw results in limited information disclosure and the possibility of constrained configuration changes that should be denied, reflecting a weakness in access control (CWE‑552).
Affected Systems
The affected product is Hewlett Packard Enterprise’s Fabric Composer networking appliance. The advisory does not list specific firmware or software versions, so administrators should verify that their deployed instance is covered by the latest vendor updates.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the absence of an EPSS value as well as no listing in the CISA KEV catalog suggest that large‑scale exploitation is currently unlikely. Because the exploit requires authenticated access, the threat is limited to organizations that do not enforce strict role segregation. Even so, the most effective mitigation is to obtain and deploy the vendor’s firmware patch or otherwise tighten API permissions.
OpenCVE Enrichment