9.6
CVE-2026-19766
- EPSS 0.27%
- Veröffentlicht 01.09.2026 19:30:38
- Zuletzt bearbeitet 04.09.2026 20:06:43
- Erkennungen
Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric Composer
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Fabric Composer Version >= 7.0.0 <= 7.3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.181 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US