Impact
The vulnerability is an authentication bypass in the REST API of HPE EdgeConnect SD‑WAN Orchestrator. It allows an unauthenticated attacker to spoof HTTP headers and gain full system access without standard login procedures. The attacker can then read or alter sensitive configuration data and system functions, compromising both confidentiality and integrity of the orchestrator.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Orchestrator. No specific version information is provided, so all deployments of this product should be treated as vulnerable until a vendor‑issued fix is applied.
Risk and Exploitability
The CVSS score is 9.8, indicating a very high severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated connection that supplies forged HTTP headers to the REST API; this inference comes from the description of the bypass. An adversary with network access to the orchestrator can exploit the flaw without needing prior authentication, making it a significant threat to organizations relying on this SD‑WAN solution.
OpenCVE Enrichment