Executive brief
HPE Networking Fabric Composer is a network management platform that controls and monitors fabric switching infrastructure in data centers. An unauthenticated remote attacker can exploit a vulnerability in its API endpoint to cause a denial of service, disrupting network operations and requiring manual intervention to restore the system. The attacker may also make limited unauthorized modifications to the underlying operating system.
Technical details
The vulnerability exists in an API endpoint of HPE Networking Fabric Composer and can be exploited by an unauthenticated remote attacker over the network. Successful exploitation allows an attacker to conduct a denial of service attack, disrupting system availability, and potentially make limited unauthorized modifications to the underlying operating system. The vulnerability requires network reachability to the affected API endpoint but does not require authentication or user interaction. Manual intervention is required to restore functionality after exploitation. Patch or workaround details are available through HPE support documentation.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed