You can get it done in a short maintenance window without bothering with the insecure old version.
Get the new hardware up on 2.4.4-p3 without any extra configuration
Restore your current config to this box -- it will be your new primary
Swap in the new box in place of the old
If it all works, then you take the old hardware, install 2.4.4-p3 on it and now that's your new secondary. If it didn't work, then you still have your current 2.4.4-p2 box and can swap it back in place and then investigate why it failed. If you want an extra dose of safety, then swap out the disk in the current system so you have the running copy of 2.4.2-p1 preserved.
If you can't get enough of a maintenance window to do it properly, it's a management issue, not a technical one. Trying to force you to work with zero downtime is insane and shouldn't be encouraged.