Description
A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Published: 2026-09-01
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A weakness in the Fabric Composer interface permits an administrative user to read configuration data and other sensitive information in cleartext. The cleartext disclosure can expose credentials, network topology, or other details that could enable further attacks. This flaw is an instance of CWE‑312, which is the use of a weak cryptographic algorithm or useless encryption.

Affected Systems

Hewlett Packard Enterprise Fabric Composer. No specific versions are listed in the advisory, so all current deployment versions that include the documented interface are potentially affected.

Risk and Exploitability

The CVSS score of 2.2 indicates low severity and the EPSS score is not provided, suggesting exploitation is unlikely. The vulnerability requires authenticated administrative access to the management interface. The flaw is not listed in CISA’s KEV catalog, and there is no public exploit known at this time.

Generated by OpenCVE AI on September 2, 2026 at 01:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware and software patches released by HPE for Fabric Composer to fix the disclosure bug.
  • Limit administrative privileges and enforce least‑privilege access to the Fabric Composer management interface.
  • Disable or remove unnecessary interfaces and services that expose sensitive data.
  • Monitor and audit administrative activity for signs of data exfiltration or privilege misuse.

Generated by OpenCVE AI on September 2, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) fabric Composer

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks fabric Composer
CPEs cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks fabric Composer

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Title Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Fabric Composer
Hewlett Packard Enterprise (hpe) Fabric Composer
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-01T20:24:55.713Z

Reserved: 2026-08-13T16:38:10.813Z

Link: CVE-2026-73748

cve-icon Vulnrichment

Updated: 2026-09-01T20:05:55.818Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:22.543

Modified: 2026-09-02T15:14:06.813

Link: CVE-2026-73748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:43:53Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information