Impact
A local authenticated user with high privileges on HPE Networking Instant On can exploit a flaw in the underlying operating system to read protected data. The vulnerability allows access to information that an attacker could use to move laterally or compromise additional network services, but only if conditions outside the attacker’s control are met. This constitutes an information exposure weakness and could lead to confidentiality loss.
Affected Systems
The affected product is HPE Networking Instant On. No specific firmware or software versions are cited in the advisory, so all current releases should be reviewed against HPE’s support documentation.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate severity vulnerability. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is local and requires authenticated access with high privileges. Because exploitation depends on external preconditions, the risk of impact may vary, but organizations should consider the potential for an attacker to gain data useful for further compromise.
OpenCVE Enrichment