CRITICAL🇬🇧 English

CVE-2026-73700

CVSS 9.0v3.1pub. 2026-09-01upd. 2026-09-02

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Arubanetworks Fabric Composer

    APP
    Arubanetworks
    < 7.3.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2026-76657CRITICAL10.0ten sam produkt

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow...

CVE-2026-76658CRITICAL10.0ten sam produkt

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an un...

CVE-2026-19766CRITICAL9.6ten sam produkt

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Comp...

CVE-2026-73701CRITICAL9.0ten sam produkt

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networ...

CVE-2026-73703HIGH8.8ten sam produkt

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthe...