Executive brief
HPE's Analytics and Location Engine (ALE) is a network positioning system used to track and locate devices. A flaw in how it handles incoming network connections allows an unauthenticated attacker to inject malicious data without authentication. This could lead to unauthorized access or data manipulation within the system.
Technical details
The vulnerability exists in socket connection handling within the ALE component, where improper input validation allows unauthenticated remote attackers to send specially crafted packets during connection establishment. The attack requires only network access with no authentication or user interaction. Successful exploitation enables unauthorized data injection into the ALE process.
Affected products
- HPE Analytics and Location Engine
Timeline
- 2026-09-22: disclosed