Impact
A buffer overflow in the API endpoint of HPE Networking Instant On allows an authenticated attacker with administrative privileges to disrupt the normal operation of the service, which restarts automatically without manual intervention. The flaw is a classic input validation error consistent with CWE‑119, and it results in a service interruption rather than arbitrary code execution.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise’s Instant ON product. No specific version information was supplied in the available data, so all released releases should be reviewed for the presence of this flaw.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity posture; the EPSS score is not available and the issue is not listed in CISA’s KEV catalog. The flaw requires an authenticated administrator, implying that the attack vector is most likely local or network-provided authentication rather than a remote attack. Because no public exploits are known, the likelihood of exploitation appears low, but the impact of an interrupting restart mandates monitoring and control of API access.
OpenCVE Enrichment