Impact
A flaw in the API of HPE EdgeConnect SD-WAN Gateways allows a remote user with only basic authentication rights to bypass normal authorization checks and gain administrative control over the web‑management interface. This privilege escalation can give the attacker full system compromise, enabling modification of network policies, extraction of sensitive data, and potential further lateral movement within the enterprise network.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or hardware revision numbers are disclosed in this advisory, so the issue applies to all versions deployed in the field until a vendor‑issued fix is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability, while the EPSS score is not available. The fact that the vulnerability is not yet listed in CISA’s KEV catalog suggests that a widespread, publicly available exploit has not yet been reported, however the impact remains severe. Successful exploitation requires the attacker to be authenticated to the API, but the attack can be executed remotely from outside the host network, making it a realistic risk in many environments.
OpenCVE Enrichment