Impact
A vulnerability in the web-based management interface of HPE Networking Fabric Composer allows an unauthenticated remote attacker to read files located within a specific system directory. The flaw results in limited disclosure of sensitive information, potentially revealing configuration data or other private files. No execution or privilege escalation is possible; the impact is restricted to confidentiality, but the exposure of internal files could aid future attacks.
Affected Systems
The affected product is Hewlett Packard Enterprise (HPE) Fabric Composer. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that there are no known widespread exploits at this time. The likely attack vector is a remote web request to the unauthenticated management interface, which does not require authentication. While the risk of exploitation is moderate, the availability of the flaw to unauthenticated users poses a tangible confidentiality threat.
OpenCVE Enrichment