Impact
The vulnerability lies in the API of the EdgeConnect SD‑WAN Orchestrator, allowing an unauthenticated remote actor to bypass authentication controls. Successful exploitation would grant administrative privileges, effectively giving an attacker complete control over the orchestrator host. This flaw is categorized as improper authentication. The consequences include full system compromise, potential data exfiltration, and the ability to pivot within the network.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. No specific version information is provided in the advisory, so all deployed instances should be considered vulnerable until a vendor update is applied.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is highly severe. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is remote access via the exposed API, where an attacker can send crafted requests without authentication. The exploitation requires network reachability to the API endpoint and does not require any local privileges.
OpenCVE Enrichment