Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise.
Published: 2026-09-01
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An unauthenticated remote attacker can query the web‑based management interface of HPE Networking Fabric Composer and retrieve certain data in cleartext. This disclosure could expose other network infrastructure components and provide input for further compromise. The weakness is classified as Ciphertext Transmission of Sensitive Information (CWE‑319).

Affected Systems

The target is the HPE Networking Fabric Composer management interface. No specific version range was supplied, so any installation of Fabric Composer is potentially affected until a vendor update is applied.

Risk and Exploitability

The CVSS score of 3.7 indicates a low severity vulnerability; the EPSS score is not available, so the likelihood of exploitation is uncertain but not considered high. The vulnerability is not listed in CISA KEV. The likely attack vector is remote access over the network to the web interface, and because authentication is not required, an attacker can probe the system from any reachable IP address, subject to network segmentation or firewall controls.

Generated by OpenCVE AI on September 2, 2026 at 02:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update HPE Fabric Composer to the latest release that contains the fix for this information disclosure.
  • If a patch cannot be applied immediately, restrict external access to the Fabric Composer web interface by firewall rules or VPN so that only trusted internal IP addresses can reach it.
  • Ensure the interface uses HTTPS to encrypt traffic and reduce the risk of data being exposed in transit.
  • Monitor access logs for unusual or unauthenticated requests to the Fabric Composer interface.

Generated by OpenCVE AI on September 2, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise.
Title Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric Composer
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:51.233Z

Reserved: 2026-08-13T16:38:10.813Z

Link: CVE-2026-73743

cve-icon Vulnrichment

Updated: 2026-09-01T20:08:08.293Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:21.960

Modified: 2026-09-03T15:12:43.320

Link: CVE-2026-73743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:44:00Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information