Executive brief
HPE Networking Fabric Composer is a web-based management tool used to configure and monitor network fabric switches. A command injection vulnerability in its web interface allows unauthenticated attackers to execute arbitrary commands on the underlying system, potentially leading to complete compromise of the device and the network infrastructure it manages.
Technical details
A command injection vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. The vulnerability can be exploited by an unauthenticated remote attacker over the network to execute arbitrary commands on the underlying host operating system. Successful exploitation requires certain preconditions outside of the attacker's control to be met. If exploited, an attacker gains the ability to execute arbitrary OS-level commands, resulting in complete system compromise including data access, service disruption, and lateral movement within the network.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed