Impact
Vulnerabilities in the EdgeConnect SD‑WAN Orchestrator API enable a remote attacker who is authenticated with low‑privilege credentials to perform server‑side request forgery (SSRF). A successful exploit permits enumeration of internal host structures and disclosure of data beyond what the user’s role normally authorizes, compromising confidentiality and potentially revealing sensitive network topology or configuration details.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific version information is provided in the advisory, so all current releases may be impacted until a vendor‑issued update becomes available.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity flaw. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread, documented exploitation at this time. Exploitation requires authenticated access with low‑privilege rights, so attackers must first compromise an account or reuse legitimate credentials. Once access is achieved, the SSRF can reach internal services and expose data that should not be exposed to those credentials.
OpenCVE Enrichment