{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-44877",
        "assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
        "state": "PUBLISHED",
        "assignerShortName": "hpe",
        "dateReserved": "2026-05-07T21:29:22.243Z",
        "datePublished": "2026-07-07T19:03:35.253Z",
        "dateUpdated": "2026-07-07T20:31:53.068Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
                "shortName": "hpe",
                "dateUpdated": "2026-07-07T19:03:35.253Z"
            },
            "title": "Unauthenticated Remote Disclosure of Cryptographic Secrets",
            "datePublic": "2026-07-07T16:00:00.000Z",
            "affected": [
                {
                    "vendor": "Hewlett Packard Enterprise (HPE)",
                    "product": "HPE Networking Instant On",
                    "platforms": [
                        "Switch Model 1830",
                        "Switch Model 1930",
                        "Switch Model 1960"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "3.0.0",
                            "lessThanOrEqual": "3.3.3",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "affected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05038en_us&docLocale=en_US"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 6.5,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Aaron P. Davis",
                    "type": "reporter"
                }
            ],
            "source": {
                "advisory": "HPESBNW05038",
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-200",
                                "lang": "en",
                                "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-07T20:31:39.854857Z",
                                "id": "CVE-2026-44877",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-07T20:31:53.068Z"
                }
            }
        ]
    }
}