Impact
A memory corruption bug in the affected interface of HPE Networking Instant On can be triggered by an unauthenticated remote attacker, causing a denial of service. The impact is limited to interrupting the normal operation of the affected service, and an attacker may obtain some restricted information from within the component.
Affected Systems
Affected products include Hewlett Packard Enterprise’s HPE Instant On service. Version details are not provided.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating a moderate risk level. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, accessed through the exposed interface, and no authentication is required. Exploitation would likely involve sending crafted input that corrupts memory, leading to an interrupt of the service and potential disclosure of limited component data.
OpenCVE Enrichment