Impact
A flaw in the HPE Networking Fabric Composer API allows an authenticated low‑privilege operator user to trigger a denial of service. The vulnerability could let an attacker interrupt the normal operation of the service, causing a loss of availability. It is classified as a resource‑consumption weakness (CWE‑400).
Affected Systems
Hewlett Packard Enterprise Fabric Composer is affected. The flaw applies to any instance of the Fabric Composer API where an authenticated low‑privilege operator has access rights, and no specific version constraints have been published.
Risk and Exploitability
The CVSS score is 3.1, indicating low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation. The likely attack vector requires legitimate authentication to the API, after which the attacker can perform repeated or crafted calls to induce a denial of service.
OpenCVE Enrichment