Impact
Multiple vulnerabilities in the REST API of Hewlett Packard Enterprise EdgeConnect SD‑WAN Orchestrator enable an unauthenticated attacker to bypass web authentication mechanisms and manipulate system functions. The flaw is an authentication bypass (CWE‑306), allowing the attacker to view and modify potentially sensitive information without valid credentials.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Orchestrator across all releases. Because no specific version range is disclosed, every deployment of this product is considered at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑severity flaw. Exploitation can be achieved remotely by sending crafted HTTP requests to the REST API endpoint, requiring no user interaction. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, its unauthenticated and remote nature poses a significant risk. The likely attack vector, inferred from the description, involves spoofing HTTP headers to subvert authentication checks and gain access to privileged API operations.
OpenCVE Enrichment