PT-2025-4796 · Hewlett Packard · Hpe Aruba Networking Fabric Composer

Published

2025-01-10

·

Updated

2025-01-28

·

CVE-2025-23054

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HPE Aruba Networking Fabric Composer (affected versions not specified)
Description A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer is related to access control errors. This issue could allow an authenticated low-privilege operator user to perform operations not permitted by their privilege level. Successful exploitation could enable an attacker to manipulate user-generated files, potentially leading to unauthorized changes in critical system configurations. An attacker could also remotely elevate their privileges, access protected information, and modify system settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01329
CVE-2025-23054

Affected Products

Hpe Aruba Networking Fabric Composer