Impact
A vulnerability in the EdgeConnect SD‑WAN Orchestrator API permits an authenticated attacker with low privileges to access sensitive information beyond the authorized scope of their account. Successful exploitation could expose data that might enable further compromise of network services managed by the Orchestrator. The flaw results from insufficient authorization checks, leading to an information disclosure vulnerability.
Affected Systems
The affected product is Hewlett Packard Enterprise's EdgeConnect SD‑WAN Gateways. No version range is specified in the advisory, so all releases of the Orchestrator API should be reviewed until vendor confirms the fix.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires valid API credentials, but an authenticated user with even low‑level privileges can abuse the flaw. Remote attackers can retrieve confidential data over the network, and the disclosed information could form a stepping‑stone for further lateral movement or privilege escalation within the organization.
OpenCVE Enrichment