Impact
A flaw in the EdgeConnect SD‑WAN Orchestrator API allows an authenticated user with low privileges to bypass authorization controls and gain full administrative rights. This privilege escalation can enable the attacker to alter network policies, inject traffic, or pivot to other services within the SD‑WAN environment, thereby compromising confidentiality, integrity, and availability of the network.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways, specifically the Orchestrator API component. No version range is identified in the advisory data.
Risk and Exploitability
The CVSS score of 9.9 reflects a critical severity. The EPSS score is less than 1%, indicating a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, but its potential to turn a low‑privileged, authenticated user into a full administrator remains a serious risk. The likely attack vector is through the network‑facing API, requiring only legitimate authentication credentials.
OpenCVE Enrichment