7.1
CVE-2026-73723
- EPSS 0.35%
- Veröffentlicht 01.09.2026 19:46:58
- Zuletzt bearbeitet 02.09.2026 16:17:21
- Erkennungen
Authenticated Privilege Escalation Leading to Unauthorized State Changes in HPE Networking Fabric Composer Web-Based Management Interface
A privilege escalation vulnerability exists in the web-based management interface of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to complete state-changing actions that should not be allowed by their current level of authorization on the platform.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Fabric Composer Version < 7.3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.276 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US