{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Networking has released updates for HPE Networking Analytics and Location Engine (ALE) that address multiple vulnerabilities described in this advisory.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect the following HPE Networking Analytics and Location Engine (ALE) versions unless specifically noted otherwise in the details section:\n    - ALE 5.0.0.0 and below\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVEs. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "These vulnerabilities were discovered by internal security research at HPE Networking. HPE Networking is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory. Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at:\nhttps://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us\n \nFor reporting *NEW* HPE Networking security issues, email can be sent to networking-psirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at:\nhttps://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: networking-psirt(at)hpe.com - For further details please see http://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported. A security vulnerability is defined as any weakness in a product that allows an attacker to compromise the confidentiality, integrity, or availability of a product, customer infrastructure, or IT system through an HPE Aruba Networking product in that environment.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "summary": "HPE Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Multiple Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)",
    "tracking": {
      "current_release_date": "2026-09-22T16:00:00.000Z",
      "generator": {
        "date": "2026-09-21T21:23:29.737Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "HPESBNW05137",
      "initial_release_date": "2026-09-22T16:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-22T16:00:00.000Z",
          "number": "1",
          "summary": "Initial Publication"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ALE 5.1.0.0",
                "product": {
                  "name": "HPE Networking Analytics and Location Engine (ALE)",
                  "product_id": "ALE-5.1.0.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=0.0.0.0|<=5.0.0.0",
                "product": {
                  "name": "HPE Networking Analytics and Location Engine (ALE)",
                  "product_id": ">=0.0.0.0|<=5.0.0.0"
                }
              }
            ],
            "category": "product_name",
            "name": "ALE"
          }
        ],
        "category": "vendor",
        "name": "HPE Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76708",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known default credentials.\n\nSuccessful exploitation could result in an attacker gaining unauthorized access to the application's management interface and the underlying operating system, potentially leading to full system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-961",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76709",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-960",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76710",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could result in the disclosure of sensitive site hierarchy, infrastructure details, and client device information.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-963",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76711",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could result in unauthorized data injection.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-969",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76712",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security controls, or a denial of service condition on the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-970",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76713",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-966",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Authenticated Remote File System Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76714",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-959, VULN-965",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Authenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76715",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-967",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76716",
      "notes": [
        {
          "category": "details",
          "text": "Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could result in a denial of service condition or unauthorized access to sensitive information.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-971",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Unauthorized Access and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76717",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure of sensitive user information, including password hashes, which could be used to facilitate further attacks.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-964",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ALE-5.1.0.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=5.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-22T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Analytics and Location Engine (ALE) software to the following version(s) (as applicable):\n    - ALE 5.1.0.0\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com/home/.",
          "product_ids": [
            "ALE-5.1.0.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=5.0.0.0"
          ]
        }
      ],
      "title": "Unauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)"
    }
  ]
}