HPE Aruba Networking Fabric Composer Authenticated Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer, specifically in version 7.1.0 and prior. This vulnerability allows an authenticated low-privilege operator user to perform actions beyond their assigned privilege level. Exploitation of this issue could enable manipulation of user-generated files, potentially resulting in unauthorized modifications to critical system configurations.

Impact

Successful exploitation could lead to unauthorized changes in important system settings, allowing low-privilege users to access or modify files and configurations they typically would not be allowed to.

Remediation

Users can upgrade to HPE Aruba Networking Fabric Composer version 7.1.1 or above to address this vulnerability. The updated version is available for download from the HPE Networking Support Portal.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.