Executive brief
HPE Networking Fabric Composer is a networking management platform used to configure and monitor fabric infrastructure. An unauthenticated remote attacker can execute arbitrary commands on the underlying host with privileged access if certain preconditions are met, potentially leading to complete compromise of the management system and the infrastructure it controls.
Technical details
A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. The vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with privileged user rights on the underlying host, contingent upon certain preconditions outside the attacker's control being satisfied. Successful exploitation results in complete compromise of the affected Fabric Composer host, granting the attacker full control over the system and potentially the entire fabric infrastructure it manages. The attack vector is network-based and does not require prior authentication.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed