Executive brief
HPE's Analytics and Location Engine (ALE) is a network management and location tracking system used in enterprise environments. An unauthenticated attacker can send specially crafted requests to the management interface to extract sensitive information including site hierarchy, infrastructure details, and device data. This could expose critical details about network topology and connected devices to unauthorized parties.
Technical details
The vulnerability is an unauthenticated information disclosure in the ALE management interface via specially crafted requests to internal endpoints. An attacker with network access to the management interface can bypass authentication to retrieve sensitive site hierarchy, infrastructure, and client device information. The attack requires no user interaction and affects the management plane directly.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed