Impact
An unauthenticated remote attacker can query the web‑based management interface of HPE Networking Fabric Composer and retrieve certain data in cleartext. This disclosure could expose other network infrastructure components and provide input for further compromise. The weakness is classified as Ciphertext Transmission of Sensitive Information (CWE‑319).
Affected Systems
The target is the HPE Networking Fabric Composer management interface. No specific version range was supplied, so any installation of Fabric Composer is potentially affected until a vendor update is applied.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity vulnerability; the EPSS score is not available, so the likelihood of exploitation is uncertain but not considered high. The vulnerability is not listed in CISA KEV. The likely attack vector is remote access over the network to the web interface, and because authentication is not required, an attacker can probe the system from any reachable IP address, subject to network segmentation or firewall controls.
OpenCVE Enrichment