Impact
The flaw resides in the HPE Networking Fabric Composer API, allowing an authenticated attacker with administrative privileges to retrieve sensitive information in cleartext. This breach of confidentiality is an instance of CWE‑200: Information Exposure, exposing data that should remain protected within the system.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise Fabric Composer. No specific software versions are enumerated, so all deployments of the product should be examined for exposure.
Risk and Exploitability
The CVSS score of 4.4 denotes moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, indicating that it is not widely exploited at this time. The attack requires authenticated administrative access, so the risk is scoped to organizations where such privileges may have been compromised or where segregation of duties is insufficient.
OpenCVE Enrichment