Impact
A flaw in the underlying operating system of HPE Networking Fabric Composer permits an authenticated operator with low privileges and local access to read sensitive data. The data exposed could subsequently aid an attacker in escalating privileges on the same system. The weakness corresponds to inadequate protection of confidential information.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise Fabric Composer devices. No specific firmware or software version numbers are listed in the CNA data, indicating that the issue may exist across available releases until a vendor fix is deployed.
Risk and Exploitability
The CVSS score of 4.7 classifies the flaw as moderate severity. Because the exploit requires local authenticated access, it cannot be triggered remotely and its EPSS score is not provided. The vulnerability is not recorded in CISA’s KEV catalog, suggesting no known public exploitation. Nonetheless, the potential for privilege escalation warrants prompt attention.
OpenCVE Enrichment