Impact
The vulnerability is a local path traversal flaw in the command line interface of HPE Networking Instant On. An authenticated administrator can craft commands that navigate outside the intended directories, allowing the modification of a restricted set of operating system files. The attacker’s actions can disrupt the normal operation of the service, effectively causing a denial‑of‑service condition for legitimate users.
Affected Systems
Affected systems include HPE Networking Instant On devices. No specific firmware or software version information is provided, so any deployment running the product may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 3 indicates low severity, and the EPSS score is unavailable. The flaw is not listed in the CISA KEV catalog. Exploitation requires administrative privileges on the CLI, so the threat is limited to users with those rights. Nonetheless, the ability to alter system files and interrupt service can remain a concern in environments where privileged users are numerous or oversight is weak.
OpenCVE Enrichment