Impact
The vulnerability allows an authenticated user with low privileges to bypass authorization controls in the EdgeConnect SD‑WAN Or an attacker can elevate privileges to an administrative level, enabling full system compromise. The weakness stems from improper access control in the API layer and can lead to unauthorized configuration changes and data exposure.
Affected Systems
EdgeConnect SD‑WAN Gateways from Hewlett Packard Enterprise. Version details are not specified in API endpoint is susceptible.
Risk and Exploitability
The severity is high, reflected by a CVSS score of 9.9. Exploitation requires remote authenticated access to the API. The EPSS score indicates a very low probability of exploitation (< 1%), and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the risk remains significant for environments that expose the API to any remote users.
OpenCVE Enrichment