{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Networking has released updates for Instant ON APs that address multiple vulnerabilities described in this advisory.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect the following HPE Networking Instant ON APs Versions unless specifically noted otherwise in the Details section:\n\n    - Instant ON 3.4.1.0 and below\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "These vulnerabilities were generally discovered by internal security research at HPE Networking. HPE Networking is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory. Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at:\nhttps://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us\n \nFor reporting *NEW* HPE Networking security issues, email can be sent to networking-psirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at:\nhttps://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: networking-psirt(at)hpe.com - For further details please see http://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported. A security vulnerability is defined as any weakness in a product that allows an attacker to compromise the confidentiality, integrity, or availability of a product, customer infrastructure, or IT system through an HPE Aruba Networking product in that environment.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "summary": "HPE Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Multiple Vulnerabilities in HPE Networking Instant ON Access-Points (APs)",
    "tracking": {
      "current_release_date": "2026-09-29T16:00:00.000Z",
      "generator": {
        "date": "2026-09-25T20:02:30.191Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.13"
        }
      },
      "id": "HPESBNW05150",
      "initial_release_date": "2026-09-29T16:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-29T16:00:00.000Z",
          "number": "1",
          "summary": "Initial Publication"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "Instant ON 3.4.2.0",
                "product": {
                  "name": "HPE Networking Instant ON APs",
                  "product_id": "3.4.2.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=0.0.0.0|<=3.4.1.0",
                "product": {
                  "name": "HPE Networking Instant ON APs",
                  "product_id": ">=0.0.0.0|<=3.4.1.0"
                }
              }
            ],
            "category": "product_name",
            "name": "Instant ON"
          }
        ],
        "category": "vendor",
        "name": "HPE Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76721",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1040",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76722",
      "notes": [
        {
          "category": "details",
          "text": "Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1055, VULN-1056",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76723",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1038, VULN-1039, VULN-1041, VULN-1042, VULN-1043, VULN-1035, VULN-1036",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.6,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.7,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "temporalScore": 9.6,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76724",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1044",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.6,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.7,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "temporalScore": 9.6,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76725",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1045",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.6,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.7,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "temporalScore": 9.6,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76726",
      "notes": [
        {
          "category": "details",
          "text": "An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1063",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76727",
      "notes": [
        {
          "category": "details",
          "text": "Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1050, VULN-1062",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76728",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1061",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76729",
      "notes": [
        {
          "category": "details",
          "text": "A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1054",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.6,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 6.6,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76730",
      "notes": [
        {
          "category": "details",
          "text": "An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1037",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76731",
      "notes": [
        {
          "category": "details",
          "text": "An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1046",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authentication Bypass in the Captive Portal of HPE Networking Instant On"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76732",
      "notes": [
        {
          "category": "details",
          "text": "A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1051",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76733",
      "notes": [
        {
          "category": "details",
          "text": "A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1057",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 4.9,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 4.9,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76734",
      "notes": [
        {
          "category": "details",
          "text": "A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1053",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 4.8,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 4.8,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76735",
      "notes": [
        {
          "category": "details",
          "text": "A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1048",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 4.1,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 4.1,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76736",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1049",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 3.3,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "environmentalScore": 3.3,
            "environmentalSeverity": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 3.3,
            "temporalSeverity": "LOW",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76737",
      "notes": [
        {
          "category": "details",
          "text": "An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1047",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 3,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "environmentalScore": 3,
            "environmentalSeverity": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 3,
            "temporalSeverity": "LOW",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "This vulnerability was discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76738",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1058",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "3.4.2.0"
        ],
        "known_affected": [
          ">=0.0.0.0|<=3.4.1.0"
        ]
      },
      "remediations": [
        {
          "category": "workaround",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        },
        {
          "category": "vendor_fix",
          "date": "2026-09-29T16:00:00.000Z",
          "details": "In order to address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking Instant ON APs software to the following version (as applicable):\n\n    - Instant ON 3.4.2.0 and above.\n\nSoftware versions with resolution/fixes for the disclosed vulnerabilities will be applied to the affected APs automatically by the Instant On cloud management portal.\n\nProduct software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not completely addressed by this security advisory. For deployments running software versions that are past End of Support (EoST), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "3.4.2.0"
          ],
          "url": "https://networkingsupport.hpe.com/home/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "environmentalScore": 2.7,
            "environmentalSeverity": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 2.7,
            "temporalSeverity": "LOW",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            ">=0.0.0.0|<=3.4.1.0"
          ]
        }
      ],
      "title": "Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service"
    }
  ]
}