Executive brief
HPE Networking Instant On switches are used to manage and secure business network traffic. A security flaw has been identified that could allow an unauthorized person to remotely access sensitive cryptographic keys and secrets stored on the device. If exploited, this could allow an attacker to decrypt traffic or gain further unauthorized access to the network infrastructure.
Technical details
An information disclosure vulnerability exists in the management interface of HPE Networking Instant On 1830, 1930, and 1960 switches. The flaw allows a remote attacker to retrieve sensitive cryptographic secrets from the system. While the advisory description mentions 'unauthenticated' access, the provided CVSS vector (PR:L) suggests that low-privileged user access may be required in some contexts. The vulnerability affects firmware versions 3.0.0 through 3.3.3. Successful exploitation results in a high impact on confidentiality by exposing secrets that could be used for further system compromise.
Affected products
- HPE Networking Instant On 1830 Switch 3.0.0 through 3.3.3
- HPE Networking Instant On 1930 Switch 3.0.0 through 3.3.3
- HPE Networking Instant On 1960 Switch 3.0.0 through 3.3.3
Timeline
- 2026-07-07: advisory: HPE published the security advisory.
- 2026-07-07: disclosed: CVE-2026-44877 was published to the NVD.