Impact
The EdgeConnect SD‑WAN Orchestrator contains server‑side request forgery weaknesses in its API that allow a user with low‑privilege authentication to craft requests to internal services. If an attacker can log in or reuse stolen credentials, the vulnerability can be used to enumerate host structures and expose sensitive configuration or topology data that falls far beyond the scope of the user’s authorized role.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. The advisory does not specify a version range, so all current releases may be vulnerable until a vendor solution is released.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity flaw, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest that widespread exploitation has not been observed yet. An attacker must first obtain or reuse low-privilege credentials to access the API, but once authenticated, the SSRF can reach internal endpoints and recover sensitive data, creating a high-risk confidentiality breach.
OpenCVE Enrichment