Impact
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets stored on a vulnerable system, exposing confidential keys and other protected material. This weakness maps to Information Exposure (CWE-200). Based on the description, it is inferred that an attacker would use the switch's exposed management interface without authentication to retrieve the secrets.
Affected Systems
The affected products are Hewlett Packard Enterprise Networking Instant On 1830, 1930, and 1960 switch models. No specific firmware versions are listed beyond the model family.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is identified as unauthenticated remote disclosure, implying that an attacker could gain information without prior authentication by connecting over the network to the switch's management interface. The leak of cryptographic secrets can have serious consequences for network security and may enable further attacks if the secrets are compromised.
OpenCVE Enrichment