Impact
A weakness in the Fabric Composer interface permits an administrative user to read configuration data and other sensitive information in cleartext. The cleartext disclosure can expose credentials, network topology, or other details that could enable further attacks. This flaw is an instance of CWE‑312, which is the use of a weak cryptographic algorithm or useless encryption.
Affected Systems
Hewlett Packard Enterprise Fabric Composer. No specific versions are listed in the advisory, so all current deployment versions that include the documented interface are potentially affected.
Risk and Exploitability
The CVSS score of 2.2 indicates low severity and the EPSS score is not provided, suggesting exploitation is unlikely. The vulnerability requires authenticated administrative access to the management interface. The flaw is not listed in CISA’s KEV catalog, and there is no public exploit known at this time.
OpenCVE Enrichment