Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-23054


A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations.


Published

2025-01-28T18:15:39.147

Last Modified

2025-04-16T18:48:06.840

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks fabric_composer < 7.1.1 Yes

References