CVE-2026-44877 Details
Description
An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system.
A remote unauthenticated vulnerability allowing the disclosure of cryptographic secrets has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches running software version 3.3.3 and below. Exploitation of this vulnerability could enable an unauthenticated remote threat actor to access sensitive cryptographic information on the affected system.
Users can upgrade local web-managed switches to version 3.3.4 or above. For switches managed by the cloud-based Web-UI, upgrading to version 3.4.0 or above addresses this vulnerability. Firmware updates are available through the HPE Community Instant On documentation for the respective switch series.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05038en_us&docLocale=en_US | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |