Impact
The vulnerability is an authentication bypass in the HPE Networking Fabric Composer API that allows an attacker without credentials to gain administrative privileges. The flaw can lead to complete compromise of the host, exposing all fabric management functions and sensitive network configuration data. The weakness corresponds to CWE‑287, which defines improper authentication control and allows unauthorized access.
Affected Systems
The affected product is Hewlett Packard Enterprise Fabric Composer. No specific version range is listed in the supplied information, so all installations of Fabric Composer are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. Because the exploit can be performed remotely and without authentication, the likelihood of exploitation is high from an attacker’s perspective, despite the EPSS score being unavailable. The vulnerability is not listed in the CISA KEV catalog, but the lack of mitigation makes it a significant risk for anyone operating Fabric Composer.
OpenCVE Enrichment