Impact
The HPE Networking Fabric Composer API contains an access‑control flaw that lets an authenticated operator with low privileges read certain system files beyond the authorized scope, potentially exposing sensitive configuration data.
Affected Systems
Hewlett Packard Enterprise’s Fabric Composer product is affected. No specific version information was listed in the advisory, so any deployed instance of Fabric Composer may be vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker would need legitimate credentials for a low‑privilege operator account and access to the API, making it an authenticated attack. Once exploited, the attacker can read selected system files but cannot execute arbitrary code or modify data, so the risk is confined to data exposure.
OpenCVE Enrichment