CVE-2026-44877

MEDIUM

Hewlett Packard Enterprise (HPE) HPE Networking Instant On - Unauthenticated Remote Disclosure of Cryptographic Secrets

Title source: rule
STIX 2.1

Description

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Hewlett Packard Enterprise (HPE)/HPE Networking Instant On 3.0.0 - 3.3.3
Published Jul 07, 2026
Tracked Since Jul 08, 2026