-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Aruba Networking Product Security Advisory ============================================== Advisory ID: HPESBNW05038 CVE: CVE-2026-44877 Publication Date: 2026-JUL-07 Status: Confirmed Severity: Medium Revision: 1 Title ===== HPE Networking Instant On Switch Remote Unauthenticated Disclosure of Cryptographic Secrets Overview ======== HPE Networking has discovered a vulnerability which discloses cryptographic secrets to an unauthenticated remote threat actor. Affected Products ================= HPE Networking Instant On 1830, 1930, and 1960 switches running software version - 3.3.3 and below NOTE: By default, the vulnerable component identified in this advisory is disabled for 1830, 1930, and 1960 cloud-managed switches. This does not apply to switches managed by a local Web-UI. HPE Networking recommends applying these software upgrades to devices before applying any non-default configurations to avoid exposure to the below vulnerability. Unaffected Products =================== Any other HPE Networking products and software versions not specifically listed above are not affected by these vulnerabilities. Details ======= Unauthenticated Remote Disclosure of Cryptographic Secrets (CVE-2026-44877) - --------------------------------------------------------------------- An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system. Internal references: VULN-127 Severity: Medium CVSS v3.1 Base Score: 6.5 CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Discovery: This vulnerability was discovered by Aaron P. Davis. Resolution ========== NOTE: This vulnerability is resolved differently depending on your HPE Networking Instant On management configuration. Upgrading local web-managed switches to version 3.3.4 or above addresses this vulnerability. Upgrading Instant On switches managed by the cloud-based Web-UI to version 3.4.0 or above addresses this vulnerability Firmware can be manually updated with the download from here: https://community.instant-on.hpe.com/viewdocument/instant-on-1830-switching-softwar https://community.instant-on.hpe.com/viewdocument/1930-software https://community.instant-on.hpe.com/viewdocument/instant-on-1960-switching-softwar HPE Networking does not evaluate or patch software branches that have reached their End of Support Life (EoSL) milestone. For more information about HPE Networking products End of Support policy visit: https://hpe.com/psnow/doc/a00143052enw Workaround ========== To minimize the likelihood of an attacker exploiting this vulnerability, HPE Aruba Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above. You may contact HPE Services Aruba Networking for any configuration assistance if needed. Exploitation and Public Discussion ================================== HPE Networking is not aware of any public discussion or exploit code targeting this specific vulnerability as of the release date of the advisory. Revision History ================ Revision 1 / 2026-JUL-07 / Initial release HPE Networking SIRT Security Procedures ============================================== Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at: http://www.hpe.com/support/security-response-policy For reporting NEW HPE Networking security issues, email can be sent to aruba-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmpNN5oXHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A6HWAwAxXe6Wk6rqcaOcaqEJS8/s02k mfE2jFFiwaJ+Qcne/buoImFxWB7DA4g3NxSr3MEKn9GFLPgfHe1l5DvaF0BQwT/V 6E45fWYCEreZD7Ts+F9QsTHwgqZkhdJzy06BaX9p+GL+Apssu9FIrbO++UTNG4Bd uggiafugX0uk2TYgFMIVVtCck6SSyGuSVgz6xzSg/Mog4JUhvg9yh+Jx794hrsC9 hbum9xd4jGnrm56c/YFdwG1+TGzUVg+Tu1xfwf7K7XYZAwIIiQtbxNP3wEbkZzHz Q3jttYfYBoYVNtlA3oW8hLT/BWdf/v+eUrA3J6V4v2TMljFjqkrvLD5iFpohvNze Vu8Rd6fbf/SUzIorNjeYhQqNbnpmVtAtox5sd+lrQCGbO0nHUpwh4UlThcK90Rc+ 2mbnjJ+zfZmPmKMPPFoPomNxjZc1diINbjgP552UE2XUmzXVRfr2D7LQe2RK+Fla Il6kOB6RRa5XytGj2PbyjtRlYGYoHCmwocmyvObB =g4Mw -----END PGP SIGNATURE-----