Sceawere

Vulnerability Detail

CVE-2026-73731UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HPE Networking Fabric Composer XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
2h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
Fabric Composer
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-01T20:17:20.703Z",
  "pubdate": "2026-09-01T20:17:20.703Z",
  "executiveSummary": "A reflected cross-site scripting (XSS) vulnerability exists within the web-based management interface of HPE Networking Fabric Composer. This security flaw enables an unauthenticated, remote attacker to inject and execute arbitrary client-side script code within the security context of a victim's active session. The vulnerability stems from improper neutralization of user-supplied data before it is rendered in the browser. Successful exploitation allows an attacker to compromise the confidentiality and integrity of the victim's session, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information processed by the administrative interface. The risk is significant as it requires no prior authentication and can be weaponized through social engineering or malicious links targeting authorized users of the management console.",
  "technicalDetails": "The vulnerability is a classic reflected XSS flaw located within the web-based management interface of HPE Networking Fabric Composer. The root cause is the failure of the application to perform adequate input validation and context-aware output encoding on parameters passed through the interface. When an attacker provides a crafted input containing malicious JavaScript, the application reflects this input back into the HTTP response without proper sanitization.\nThe attack flow initiates when an unauthenticated attacker identifies an entry point—such as a URL parameter or form field—within the web interface that processes user input and subsequently reflects it in the HTML response. The attacker constructs a malicious payload containing JavaScript, often embedded within a URL. This URL is then delivered to an authenticated administrative user via social engineering, phishing, or other distribution methods.\nOnce the victim interacts with the malicious link, the application processes the request and embeds the malicious script into the HTML DOM. Because the browser interprets this injected script as being served from the trusted HPE Networking Fabric Composer origin, the script executes within the security context of the victim's session. This bypasses typical Same-Origin Policy (SOP) restrictions that would otherwise prevent cross-origin resource access.\nPost-exploitation impact is high. Upon execution, the payload can perform various malicious activities, including stealing session cookies or authentication tokens, capturing sensitive data displayed on the dashboard, performing unauthorized administrative actions on behalf of the user, or redirecting the user to malicious sites. The payload executes entirely within the victim's browser, making it difficult for server-side logs to detect the extent of the client-side compromise. The vulnerability is characterized by its remote, unauthenticated access vector, meaning no specific administrative privileges are required by the attacker to initiate the request, though the ultimate impact depends on the privileges possessed by the victim whose session is targeted."
}
CVE-2026-73731: HPE Networking Fabric Composer XSS (MEDIUM Severity, CVSS: 6.1) - Sceawere