Impact
The vulnerability is an authenticated low‑privilege denial of service in the web‑based management interface. A user with operator privileges can trigger the service to crash, leading to loss of availability of the interface and potential interruption of fabric management operations. The weakness corresponds to CWE‑400: Uncontrolled Resource Consumption. The impact is limited to availability; confidentiality and integrity are not directly affected.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. The weakness affects all versions of the web‑based management interface that have not been patched. No specific version range is listed, so all exposed installations remain vulnerable until a vendor update is applied.
Risk and Exploitability
The CVSS base score of 3.5 classifies this issue as low severity. With no EPSS data and no listing in the CISA KEV catalog, the likelihood of widespread exploitation appears low. However, the vulnerability requires authentication, so only users with operator or higher privilege on the management console pose a threat. The exploit would involve sending a crafted request to the interface once authenticated, causing the service to terminate.
OpenCVE Enrichment