Description
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Published: 2026-09-11
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: User Impersonation via SAML Response Tampering
Action: Apply Patch
AI Analysis

Impact

The vulnerability permits an attacker to tamper with SAML responses processed by HPE IceWall devices, enabling the forging or alteration of authentication assertions. Consequently, a malicious actor can impersonate a legitimate user, gaining unauthorized access to protected resources. This flaw reflects a failure in input validation when parsing SAML messages (CWE‑347).

Affected Systems

The affected product family is Hewlett Packard Enterprise’s IceWall appliance line. Exact product models and firmware versions are not detailed in the available advisory. Administrators should examine their deployed IceWall revisions and compare them against the vendor’s published release notes to determine whether they remain vulnerable.

Risk and Exploitability

The advisory assigns a CVSS score of 8.8, indicating a high severity. The EPSS score is not reported, and the vulnerability has not been listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The exploit requires remote interaction over the network, exploiting the SAML response handling logic; thus, an attacker only needs to supply a crafted SAML assertion to the appliance. The scope extends to the entire device if authentication is compromised, potentially exposing all services protected by the IceWall.

Generated by OpenCVE AI on September 11, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE IceWall firmware or patch released in the official support article linked in the advisory.
  • Configure the appliance to enforce strict validation of SAML responses, ensuring that only signed and timestamped assertions from trusted identity providers are accepted.
  • If possible, remove or disable any legacy SAML or authentication protocols that are not required for your environment to reduce the attack surface.

Generated by OpenCVE AI on September 11, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Title HPE IceWall products, Remote Bypass of Security Restrictions
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-11T06:21:56.788Z

Reserved: 2026-08-13T16:39:33.898Z

Link: CVE-2026-73784

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T07:16:46.477

Modified: 2026-09-11T07:16:46.477

Link: CVE-2026-73784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:30:10Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature