Impact
An unauthenticated path traversal flaw exists in the API endpoint of HPE Networking Fabric Composer. An attacker who can reach the API from an adjacent network segment could potentially write user‑generated files to arbitrary locations under the service’s directory. If the attacker succeeds, critical system configuration files could be altered, compromising the integrity and availability of the Fabric Composer product. The weakness is identified as CWE‑22, which addresses path traversal vulnerabilities that allow unintended file access.
Affected Systems
The affected vendor is Hewlett Packard Enterprise, product Fabric Composer. No specific version range is disclosed, so all installations of Fabric Composer that expose the vulnerable API endpoint are potentially impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated access to the exposed API endpoint from an adjacent network. Exploitation would require the attacker to be within network range and to target the vulnerable endpoint; no privileged context or user authentication is needed."
OpenCVE Enrichment