Impact
Buffer overflow vulnerabilities in the underlying operating system of HPE EdgeConnect SD-WAN Gateways enable an unauthenticated remote attacker to trigger arbitrary code execution. Successful exploitation would allow the attacker to run arbitrary commands on the host, leading to a complete compromise of the gateway system and potentially the wider network. The primary weakness is a classic buffer overflow that can be abused to overwrite control data and redirect execution flow.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways. No specific firmware or OS version information is provided in the CVE data, so all current builds fall within the affected scope until a vendor update is released.
Risk and Exploitability
The CVSS score of 9.8 reflects a high severity with unrestricted remote exploitation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication checks and the presence of a buffer overflow suggest that a network attacker could easily discover and exploit the flaw. Attackers would need to identify the vulnerable service, craft a malicious payload, and connect from an external network, which is feasible given the documented lack of controls.
OpenCVE Enrichment