Executive brief
HPE Networking Fabric Composer is a web-based management system for enterprise network fabric infrastructure. An unauthenticated attacker can exploit a vulnerability in the web interface to access sensitive data in cleartext format, potentially exposing network infrastructure credentials and configuration details that could facilitate further attacks.
Technical details
The vulnerability is an information disclosure issue in the web-based management interface of HPE Networking Fabric Composer that allows unauthenticated remote access to sensitive data. An attacker on the network can reach the web interface and extract cleartext information without authentication, potentially gaining access to credentials, configuration data, or other sensitive information handled by the management interface. This exposed data could be leveraged to compromise additional network infrastructure components. Patch availability should be confirmed with HPE security advisories.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed