ZeroHour

CVE-2026-73715

niche

Unauthenticated DoS in HPE Networking Fabric Composer API

CVSS 3.1
7.5 high
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-73715 is a denial-of-service flaw in the API of HPE Networking Fabric Composer (Aruba Networks), classified as uncontrolled resource consumption (CWE-400). An unauthenticated remote attacker can trigger it by sending crafted requests directly to the exposed API, with no user interaction or credentials required. Successful exploitation disrupts the availability of the affected interface; the CVSS vector confirms no confidentiality or integrity impact, only high availability impact. Organizations running HPE/Aruba Fabric Composer to manage their switching fabric are the affected population. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only 0.4%, indicating no observed exploitation so far.

What to do: Monitor the HPE/Aruba security advisory for CVE-2026-73715 and upgrade Fabric Composer to the fixed release it specifies (no fixed version is given in the current data). Until patched, restrict network access to the Fabric Composer API to trusted management networks and remove any direct internet exposure of the interface. Since Fabric Composer orchestrates the switching fabric, consider the operational impact of a management-plane outage and have a fallback management method ready.

Affected
HPE (Aruba Networks) Networking Fabric Composer
Estimated exposure
nichelikely on the order of thousands of management instances globally (specialized enterprise fabric-management deployments) — No public install-base figures are available, so this is estimated from Fabric Composer's deployment pattern as a specialized data-center fabric orchestration platform typically deployed as one or a few management instances per enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to disrupt the availability of the affected interface.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.