Executive brief
HPE Networking Fabric Composer is a management platform for network fabrics used in enterprise data centers. An authenticated low-privilege operator can exploit an underlying OS vulnerability to read sensitive information on the device, potentially gaining credentials or configuration data to compromise the system and connected infrastructure.
Technical details
This vulnerability exists in the underlying operating system running HPE Networking Fabric Composer. An authenticated attacker with low-privilege local access can exploit an unspecified OS-level weakness to read sensitive files or memory containing credentials, configuration details, or other confidential data. The attack requires authentication and local access to the appliance. Successful exploitation enables information disclosure that could facilitate further privilege escalation or lateral movement to other systems on the network.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed