A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to be recorded on the affected system.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to be recorded on the affected system. | |
| Title | Improper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API Endpoint | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-09-01T20:24:49.779Z
Reserved: 2026-08-13T16:38:10.813Z
Link: CVE-2026-73742
Updated: 2026-09-01T20:08:41.903Z
Status : Awaiting Analysis
Published: 2026-09-01T20:17:21.850
Modified: 2026-09-01T21:18:40.657
Link: CVE-2026-73742
No data.
OpenCVE Enrichment
No data.
Weaknesses