Description
A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

A remote, unauthenticated attacker can trigger a denial of service on the HPE IceWall Federation Agent and Proxy by abusing a weakness that permits arbitrary requests to overwhelm the service. The flaw is identified as CWE-241, indicating insufficient validation of input integrity. The resulting impact is service disruption for users relying on the affected component.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise HPE IceWall products, specifically the Federation Agent and Proxy components. No specific version information is provided, so any deployed instances of these components could be susceptible.

Risk and Exploitability

The CVSS score of 7.5 classifies this flaw as high severity, reflecting a significant risk of disruption. Although EPSS data is missing and the vulnerability is not listed in CISA KEV, the reported attack vector is remote and unauthenticated, inferred from the description. An attacker could potentially craft requests to exhaust resources and halt the service, pending the presence of the unpatched component.

Generated by OpenCVE AI on September 11, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the HPE IceWall Federation Agent and Proxy to the latest patched release that addresses the denial of service flaw
  • Configure network access controls such as IP whitelisting or rate limiting to reduce exposure of the agent/proxy to unauthenticated traffic
  • Continuously monitor system and network logs for abnormal request patterns that may indicate exploitation attempts

Generated by OpenCVE AI on September 11, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Title HPE IceWall Federation Agent and Proxy, Denial of Service vulnerability
Weaknesses CWE-241
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-11T15:52:49.508Z

Reserved: 2026-08-13T16:39:33.898Z

Link: CVE-2026-73785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T07:16:46.623

Modified: 2026-09-11T16:17:47.327

Link: CVE-2026-73785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses
  • CWE-241

    Improper Handling of Unexpected Data Type