Sceawere
Vulnerability Detail
CVE-2026-73743UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
HPE Networking Fabric Composer Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 2h ago
- Vendor
- Hewlett Packard Enterprise (HPE)
- Product
- Fabric Composer
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled by the affected interface. A successful exploit could allow an attacker to gain access to some data in a cleartext format possibly exposing other network infrastructure to further compromise.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-01T20:17:21.960Z",
"pubdate": "2026-09-01T20:17:21.960Z",
"executiveSummary": "This vulnerability involves an information disclosure flaw within the web-based management interface of HPE Networking Fabric Composer.\nThe vulnerability allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data transmitted or processed by the interface.\nThe primary risk entails the exposure of cleartext information which may include configuration details, operational metadata, or credentials, potentially facilitating lateral movement or further compromise of the associated network infrastructure.\nNo authentication is required to exploit this vulnerability, significantly increasing the risk profile for affected deployments.\nSuccessful exploitation allows attackers to bypass standard access controls to gain insight into protected internal data flows.",
"technicalDetails": "The vulnerability resides in the web-based management interface of HPE Networking Fabric Composer. The root cause is a failure in the application's access control mechanisms or improper handling of sessionless requests, which allows an unauthenticated party to query internal data handlers directly.\nBecause the interface lacks sufficient authentication enforcement for specific endpoints, an attacker can craft remote HTTP requests that bypass the intended security layer. By interacting directly with the web management interface, the attacker can solicit responses that contain sensitive, non-public data objects. In many instances, this data is rendered in cleartext, meaning no cryptographic primitives are required to parse the intercepted information.\nThe attack flow follows a direct-request pattern: 1) The attacker identifies the reachable IP address of the HPE Networking Fabric Composer management interface. 2) The attacker submits specially crafted GET or POST requests to specific, inadequately protected API endpoints or management interface paths. 3) The application, failing to validate the request origin or session integrity, returns sensitive system data. 4) The attacker captures this payload, which may contain infrastructural topology data, administrative configurations, or connectivity settings.\nThe exposure of such data is critical because HPE Networking Fabric Composer is designed to manage sophisticated network fabrics. Insight into these fabrics allows an attacker to map the network infrastructure, identify high-value targets, and ascertain internal configuration secrets that are often stored in plain text or easily reversible formats within the management interface. This provides the attacker with a roadmap for subsequent, targeted attacks against the underlying physical and virtual network infrastructure.\nThe impact of this vulnerability is high, as the exposure occurs without any interaction from legitimate users or administrative intervention. The lack of authentication requirements allows for automated, large-scale scanning and extraction of data. Once the attacker has gained this information, the post-exploitation impact includes the potential for full network discovery, enabling further compromise of the network fabric that the product manages."
}