CVE-2025-23053: Arubanetworks Fabric Composer

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

Affected products

  • Arubanetworks Fabric Composer: from 7.0.0, before 7.1.1 (fixed in 7.1.1)

Published 2025-01-28. Last modified 2026-06-17.