Impact
The vulnerability permits an attacker to tamper with SAML responses processed by HPE IceWall devices, enabling the forging or alteration of authentication assertions. Consequently, a malicious actor can impersonate a legitimate user, gaining unauthorized access to protected resources. This flaw reflects a failure in input validation when parsing SAML messages (CWE‑347).
Affected Systems
The affected product family is Hewlett Packard Enterprise’s IceWall appliance line. Exact product models and firmware versions are not detailed in the available advisory. Administrators should examine their deployed IceWall revisions and compare them against the vendor’s published release notes to determine whether they remain vulnerable.
Risk and Exploitability
The advisory assigns a CVSS score of 8.8, indicating a high severity. The EPSS score is not reported, and the vulnerability has not been listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The exploit requires remote interaction over the network, exploiting the SAML response handling logic; thus, an attacker only needs to supply a crafted SAML assertion to the appliance. The scope extends to the entire device if authentication is compromised, potentially exposing all services protected by the IceWall.
OpenCVE Enrichment