Impact
A local buffer overflow flaw exists in the operating system layer of HPE Networking Instant On, allowing a low‑privilege authenticated user to corrupt memory and interrupt service operation. The effect is a crash or forced restart of the affected component, leading to a denial‑of‑service condition. The vulnerability does not provide remote code execution, privilege escalation, or data exposure. It is a classic memory corruption weakness that disrupts availability.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise (HPE) Instant ON networking devices. No specific firmware or OS version ranges are supplied, but the flaw resides in the underlying operating system that runs the service. Administrators should verify the firmware/OS build of any HPE Networking Instant On device deployed in their environment.
Risk and Exploitability
The CVSS score of 3.3 reflects a low overall severity; the EPSS score is not available, and the issue is not listed as a known exploited vulnerability by CISA. Exploitation requires local access with authentication, limiting the attack surface. However, within a local network or administrative domain, a compromised account could trigger the buffer overflow and produce a service interruption. Attackers would need to locate the vulnerable component and have write permission, but no remote vector or elevated privilege is required.
OpenCVE Enrichment