Description
A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
Published: 2026-09-29
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

A buffer overflow in the API endpoint of HPE Networking Instant On allows an authenticated attacker with administrative privileges to disrupt the normal operation of the service, which restarts automatically without manual intervention. The flaw is a classic input validation error consistent with CWE‑119, and it results in a service interruption rather than arbitrary code execution.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise’s Instant ON product. No specific version information was supplied in the available data, so all released releases should be reviewed for the presence of this flaw.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity posture; the EPSS score is not available and the issue is not listed in CISA’s KEV catalog. The flaw requires an authenticated administrator, implying that the attack vector is most likely local or network-provided authentication rather than a remote attack. Because no public exploits are known, the likelihood of exploitation appears low, but the impact of an interrupting restart mandates monitoring and control of API access.

Generated by OpenCVE AI on September 29, 2026 at 22:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update to the latest version when it becomes available
  • Restrict access to the API endpoint to trusted administrators only, using network segmentation or firewall rules
  • Disable or remove the API endpoint if it is not required for business operations

Generated by OpenCVE AI on September 29, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
Title Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-29T19:28:58.533Z

Reserved: 2026-08-19T16:13:34.635Z

Link: CVE-2026-76738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:26.277

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-76738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:15:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer