Impact
The disclosed vulnerability in the HPE EdgeConnect SD‑WAN Orchestrator allows an attacker who has authenticated, read‑only access to the system to trigger a specially crafted request against the cache synchronization endpoint. By doing so the attacker can retrieve sensitive third‑party API tokens and credentials that are stored within the Orchestrator’s configuration. Because these credentials enable communication with external security platforms, the compromise could be used to launch lateral movement or further attacks against the wider network. The weakness is a form of sensitive data exposure resulting from inadequate access‑control checks on the cache endpoint, corresponding to CWE‑200.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways, specifically the SD‑WAN Orchestrator component. No specific version numbers are disclosed in the advisory, so all current releases of the orchestrator should be considered vulnerable until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 9.9 signifies critical severity, yet the EPSS score is less than 1%, indicating a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. The attack vector is remote and requires authenticated access with limited read‑only rights – credentials that are not uncommon in managed environments. Should an attacker acquire such credentials, the ability to pull sensitive API tokens creates a high‑impact foothold for subsequent compromise. Consequently, the threat is high, especially in environments where read‑only accounts are broadly granted or where the orchestrator interfaces with external platforms.
OpenCVE Enrichment