Impact
A denial‑of‑service flaw exists in the HPE Networking Instant On API endpoint that can be leveraged by an authenticated attacker holding administrative rights. By exploiting this vulnerability, an adversary can temporarily halt the normal operation of the service, which will subsequently recover without manual intervention. The impact is confined to service availability and does not directly affect confidentiality or integrity.
Affected Systems
Hewlett Packard Enterprise’s Instant ON platform is affected. No specific firmware or software versions are listed in the advisory, so all releases of the product are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated administrative credentials, so the threat surface is limited to trusted users or compromised accounts. Because the attack vector involves API access, the likelihood of exploitation in the wild is low but not negligible, especially in environments where API authentication is weak or oversight exists.
OpenCVE Enrichment