Impact
A flaw in the EdgeConnect SD‑WAN Orchestrator API allows a remote low‑privileged authenticated user to bypass authorization controls and gain administrative privileges, which can lead to complete system compromise by granting the attacker full control over the system.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways, specifically the Orchestrator API component. No version range is identified in the advisory data.
Risk and Exploitability
The CVSS score of 9.9 reflects a critical severity. The EPSS score is less than 1%, indicating a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, but its potential to turn a low‑privileged, authenticated user into a full administrator remains a serious risk. The likely attack vector is inferred to be through the network‑facing API, requiring only legitimate authentication credentials.
OpenCVE Enrichment