Executive brief
HPE's Analytics and Location Engine (ALE) contains hardcoded default credentials in both the application and operating system that allow unauthenticated remote attackers to log in. Successful exploitation grants attackers full access to the management interface and underlying system, enabling complete system compromise including data theft and unauthorized control.
Technical details
The Analytics and Location Engine contains hardcoded default credentials in multiple administrative and system accounts accessible without authentication. An unauthenticated remote attacker can exploit this by attempting login with known default credentials to gain direct access to both the management interface and underlying operating system. Successful authentication provides unrestricted command execution and full system control.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed