Impact
A path‑traversal weakness in the web‑based management interface of Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateway (ECOS) lets an attacker who is logged in with high privileges read, modify, or delete any file on the device. The flaw, identified as CWE‑377 and CWE‑732, threatens confidentiality, integrity, and availability of configuration files, logs, and system binaries.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS). The vulnerability affects all build versions of the web UI for ECOS; no specific firmware or model numbers are specified in the advisory.
Risk and Exploitability
The CVSS base score of 7.2 indicates moderate to high severity. The EPSS score of < 1 % shows a low likelihood of exploitation currently, and the vulnerability is not listed in CISA KEV. Exploitation requires remote authenticated access to the web interface, so the attacker must first obtain or guess valid credentials. Once authenticated, the path traversal can be leveraged to reach arbitrary paths, potentially exposing sensitive data and enabling further compromise.
OpenCVE Enrichment