Impact
The vulnerability allows an unauthenticated attacker who is adjacent to the EdgeConnect gateway to trigger a Denial‑of‑Service condition by sending crafted traffic. The attack can crash the system, preventing it from rebooting automatically, and thus disrupts network operations. This results in loss of availability for all services that depend on the gateway, with a CVSS score of 8.6 indicating high severity.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are impacted. No specific firmware or software version is listed in the advisory, so any deployment that includes the EdgeConnect gateway may be affected. The vendor’s support document outlines a patch or update that addresses the issue; administrators should refer to that documentation for details.
Risk and Exploitability
The CVSS score of 8.6 reflects a high impact availability risk. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. However, the attack requires only local network adjacency and no authentication, meaning that any device on the same local area network or VLAN can readily attempt the exploit, making it a realistic local threat for environments that lack proper segmentation.
OpenCVE Enrichment