Impact
The vulnerability in HPE Networking Fabric Composer permits an authenticated low‑privilege operator who has local access to elevate their privileges, enabling them to perform limited modifications on the affected system.
Affected Systems
The flaw affects Hewlett Packard Enterprise’s Fabric Composer product. Versions of the software distributed by HPE that do not include the vendor‑issued patch are vulnerable.
Risk and Exploitability
With a CVSS score of 2.5 the severity is low, and the EPSS score is not available, indicating no known widespread exploitation. The attack vector is local and requires authentication, so the risk is confined to individuals who already possess a low‑privilege user account. The vulnerability does not provide full system control, but it can be used to add or change configuration settings or install restricted software within the local environment. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits.
OpenCVE Enrichment