Impact
The vulnerability resides in the SSH daemon of HPE Networking Fabric Composer. It permits an attacker without authentication to gain administrative privileges and execute arbitrary commands on the underlying operating system. This grants full control over the affected Fabric Composer host, potentially compromising entire network infrastructures.
Affected Systems
Hewlett Packard Enterprise Fabric Composer devices are affected. No specific version range is listed, so all deployments of the default Fabric Composer SSH daemon should be considered vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the risk of exploitation. The likely attack vector is remote unauthenticated access over the network, requiring only the ability to reach the SSH service. Once accessed, an attacker can gain privileged access and carry out arbitrary commands, leading to complete system compromise.
OpenCVE Enrichment