Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access data beyond what is authorized by the user's existing privilege level, potentially leading to further unauthorized access.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
Hewlett Packard Enterprise (HPE) · Fabric Composer