Description
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Published: 2026-09-29
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A local buffer overflow flaw exists in the operating system layer of HPE Networking Instant On, allowing a low‑privilege authenticated user to corrupt memory and interrupt service operation. The effect is a crash or forced restart of the affected component, leading to a denial‑of‑service condition. The vulnerability does not provide remote code execution, privilege escalation, or data exposure. It is a classic memory corruption weakness that disrupts availability.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise (HPE) Instant ON networking devices. No specific firmware or OS version ranges are supplied, but the flaw resides in the underlying operating system that runs the service. Administrators should verify the firmware/OS build of any HPE Networking Instant On device deployed in their environment.

Risk and Exploitability

The CVSS score of 3.3 reflects a low overall severity; the EPSS score is not available, and the issue is not listed as a known exploited vulnerability by CISA. Exploitation requires local access with authentication, limiting the attack surface. However, within a local network or administrative domain, a compromised account could trigger the buffer overflow and produce a service interruption. Attackers would need to locate the vulnerable component and have write permission, but no remote vector or elevated privilege is required.

Generated by OpenCVE AI on September 29, 2026 at 21:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update HPE Networking Instant On to the latest firmware or operating system release that contains the vendor’s fix.
  • Restrict local account privileges and enforce least privilege so that only trusted administrators can modify the vulnerable components.
  • Monitor device logs and uptime for abnormal restarts or crashes that could indicate exploitation attempts.

Generated by OpenCVE AI on September 29, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-787

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Title Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T19:28:54.745Z

Reserved: 2026-08-19T16:13:34.635Z

Link: CVE-2026-76736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:26.027

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T21:45:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-787

    Out-of-bounds Write