Description
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: User Impersonation via SAML Response Tampering
Action: Apply Patch
AI Analysis

Impact

The vulnerability permits an attacker to tamper with SAML responses processed by HPE IceWall devices, enabling the forging or alteration of authentication assertions. Consequently, a malicious actor can impersonate a legitimate user, gaining unauthorized access to protected resources. This flaw reflects a failure in input validation when parsing SAML messages (CWE‑347).

Affected Systems

The affected product family is Hewlett Packard Enterprise’s IceWall appliance line. Exact product models and firmware versions are not detailed in the available advisory. Administrators should examine their deployed IceWall revisions and compare them against the vendor’s published release notes to determine whether they remain vulnerable.

Risk and Exploitability

The advisory assigns a CVSS score of 8.8, indicating a high severity. The EPSS score is not reported, and the vulnerability has not been listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The exploit requires remote interaction over the network, exploiting the SAML response handling logic; thus, an attacker only needs to supply a crafted SAML assertion to the appliance. The scope extends to the entire device if authentication is compromised, potentially exposing all services protected by the IceWall.

Generated by OpenCVE AI on September 11, 2026 at 07:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE IceWall firmware or patch released in the official support article linked in the advisory.
  • Configure the appliance to enforce strict validation of SAML responses, ensuring that only signed and timestamped assertions from trusted identity providers are accepted.
  • If possible, remove or disable any legacy SAML or authentication protocols that are not required for your environment to reduce the attack surface.

Generated by OpenCVE AI on September 11, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise
Hewlett Packard Enterprise hpe Icewall Products
Vendors & Products Hewlett Packard Enterprise
Hewlett Packard Enterprise hpe Icewall Products

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Title HPE IceWall products, Remote Bypass of Security Restrictions
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hewlett Packard Enterprise Hpe Icewall Products
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-11T13:46:23.240Z

Reserved: 2026-08-13T16:39:33.898Z

Link: CVE-2026-73784

cve-icon Vulnrichment

Updated: 2026-09-11T13:38:53.293Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T07:16:46.477

Modified: 2026-09-11T14:56:50.613

Link: CVE-2026-73784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:53Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature