Description
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker who is adjacent to the EdgeConnect gateway to trigger a Denial‑of‑Service condition by sending crafted traffic. The attack can crash the system, preventing it from rebooting automatically, and thus disrupts network operations. This results in loss of availability for all services that depend on the gateway, with a CVSS score of 8.6 indicating high severity.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are impacted. No specific firmware or software version is listed in the advisory, so any deployment that includes the EdgeConnect gateway may be affected. The vendor’s support document outlines a patch or update that addresses the issue; administrators should refer to that documentation for details.

Risk and Exploitability

The CVSS score of 8.6 reflects a high impact availability risk. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the attack requires only local network adjacency and no authentication, meaning that any device on the same local area network or VLAN can readily attempt the exploit, making it a realistic local threat for environments that lack proper segmentation.

Generated by OpenCVE AI on September 20, 2026 at 13:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware or software patch released by HPE for EdgeConnect SD‑WAN Gateways.
  • Restrict network access to the gateway by placing it behind a firewall or VLAN that prevents unauthenticated traffic from untrusted devices.
  • Monitor system logs and uptime to detect and respond promptly to any abnormal crashes or service interruptions.

Generated by OpenCVE AI on September 20, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-400

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-770

Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-770

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Title Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-21T19:48:14.138Z

Reserved: 2026-08-19T16:11:18.067Z

Link: CVE-2026-76679

cve-icon Vulnrichment

Updated: 2026-09-21T19:48:09.240Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:49.767

Modified: 2026-09-28T13:49:15.787

Link: CVE-2026-76679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T13:15:14Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption