Impact
The vulnerability arises from improper client address validation in a Fabric Composer API endpoint, allowing an authenticated low‑privilege operator to spoof the source address attached to their requests. This can result in inaccurate attribution records being stored on the system, potentially masking the origin of actions or misidentifying users.
Affected Systems
Hewlett Packard Enterprise Fabric Composer is affected. Version details are not provided in the advisory, but the issue applies to the current installation of the product that contains the vulnerable API. The flaw can only be exploited by users who have authenticated with low‑privilege operator rights.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability falls into the low to moderate severity range. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity to date. However, because the attack requires an authenticated low‑privilege account, the likelihood of exploitation is constrained by user access control. If exploited, the primary risk is the corruption of accurate attribution data rather than a direct compromise of confidentiality, integrity, or availability.
OpenCVE Enrichment