Executive brief
HPE Networking Fabric Composer provides a web-based interface for managing network fabric infrastructure. A denial-of-service vulnerability in this management interface allows authenticated low-privilege users to disrupt service availability, potentially taking the management console offline and preventing legitimate administrators from managing the network.
Technical details
A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. The vulnerability requires authentication as a low-privilege operator user and can be exploited to cause disruption to the affected interface's availability. The specific root cause and vulnerable component details are not disclosed in the advisory summary. Successful exploitation allows an attacker to disrupt the management interface, though the attack does not appear to lead to data exposure or lateral movement.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed