NCSC | Security Advisories
Bekijk RSS-feed

Security Advisories

Download

Security Advisory; NCSC-2026-0339 [1.0.0]

Security Advisory
NCSC-2026-0339 [1.0.0]
Publicatie
03-09-2026 15:44 (Europe/Amsterdam)
Prioriteit
Normaal
Betreft
Kwetsbaarheden verholpen in HPE Networking Fabric Composer

Kenmerken

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • External Control of File Name or Path
  • Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • Improper Control of Generation of Code ('Code Injection')
  • Authentication Bypass by Spoofing
  • Missing Authentication for Critical Function
  • Cross-Site Request Forgery (CSRF)
  • Files or Directories Accessible to External Parties
  • URL Redirection to Untrusted Site ('Open Redirect')
  • Incorrect Authorization

Omschrijving

HPE heeft meerdere kwetsbaarheden verholpen in HPE Networking Fabric Composer.

De kwetsbaarheden in HPE Networking Fabric Composer betreffen onder andere authenticatiebypasses, privilege-escalaties, remote code execution, command injection, cross-site scripting (XSS), denial-of-service, arbitrary file write, path traversal, en onbevoegde toegang tot gevoelige informatie. Sommige kwetsbaarheden kunnen door ongeauthenticeerde aanvallers op afstand worden misbruikt, terwijl andere exploitatie vereisen door geauthenticeerde gebruikers met beperkte privileges. Exploitatie kan leiden tot het verkrijgen van administratieve toegang, het uitvoeren van willekeurige commando's met verhoogde privileges, het wijzigen van systeemconfiguraties, het uitlekken van gevoelige data, en het verstoren van de normale werking van het systeem. Diverse kwetsbaarheden zijn aanwezig in de API, het onderliggende besturingssysteem en de webgebaseerde managementinterface van het product. Sommige aanvallen vereisen dat de aanvaller zich op een aangrenzend netwerk bevindt of lokale toegang heeft. De kwetsbaarheden beïnvloeden de integriteit, vertrouwelijkheid en beschikbaarheid van het systeem en de netwerkfabric-omgeving die door HPE Networking Fabric Composer wordt beheerd.

Als de SSH beheerinterface publiekelijk via het internet bereikbaar is, kan CVE-2026-76658 door ongeauthoriseerde aanvallers van buitenaf worden misbruikt voor volledige overname van het achterliggende datacenter-netwerk. Het is goed gebruik een dergelijk beheerinterface niet direct aan het internet te ontsluiten of af te schermen middels een VPN of whitelist.

Oplossingen

HPE heeft updates uitgebracht om de kwetsbaarheden in HPE Networking Fabric Composer te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Referenties

CVE's

Producten

Aruba Networks
Fabric Composer
Hewlett Packard Enterprise (HPE)
Fabric Composer

Disclaimer

The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this page to enhance access to its information and security advisories. The use of this security advisory is subject to the following terms and conditions: NCSC-NL makes every reasonable effort to ensure that the content of this page is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or continuous keeping up-to-date. The information contained in this security advisory is intended solely for the purpose of providing general information to professional users. No rights can be derived from the information provided therein. NCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of this security advisory. This includes damage resulting from the inaccuracy of incompleteness of the information contained in the advisory. This security advisory is subject to Dutch law. All disputes related to or arising from the use of this advisory will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings.