Impact
A command injection flaw exists in the CLI commands of HPE EdgeConnect SD‑WAN Gateway running ECOS. The flaw allows an authenticated remote attacker with privileged access to inject and execute arbitrary operating‑system commands. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system. The weakness maps to CWE‑77, Command Injection.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateway devices running the ECOS firmware. No specific firmware versions are listed.
Risk and Exploitability
The CVSS base score is 7.2, indicating high severity, while the EPSS score of 2% suggests that exploitation is currently unlikely at the population level. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access to the CLI, the attack vector is restricted to users who already possess privileged credentials on the device. If the attacker can obtain such credentials, they can leverage the injection point to run arbitrary commands remotely.
OpenCVE Enrichment