HPE Aruba Networking Fabric Composer
cpe:2.3:a:arubanetworks:fabric_composer:*:*:*:*:*:*:*
- <= 7.1.0
A privilege escalation vulnerability has been identified in the web-based management interface of HPE Aruba Networking Fabric Composer, version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to alter the state of certain settings on a vulnerable system. The issue arises from broken access control, which could be exploited to manipulate user-generated files and make unauthorized changes to critical system configurations.
Exploitation of this vulnerability could enable an authenticated low-privilege user to gain elevated privileges, allowing them to modify system settings and potentially disrupt normal operations or compromise system integrity.
Users can upgrade to HPE Aruba Networking Fabric Composer version 7.1.1 or above to address this vulnerability. The updated version can be downloaded from the HPE Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.