Impact
A limited buffer overflow in the network security monitoring component of the EdgeConnect intrusion detection system allows an unauthenticated remote attacker to trigger a denial‑of‑service and may enable execution of arbitrary code on the gateway. The flaw arises from insufficient bounds checking when processing externally supplied data, causing a buffer to be overrun. Successful exploitation would interrupt the gateway’s operation and could compromise the integrity of the SD‑WAN fabric.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. No specific firmware or build numbers are listed; all installations of the EdgeConnect product line should be reviewed for the existence of the buffer overflow flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity. No EPSS score is available, but the lack of exploitation data does not diminish the potential risk, particularly given the unauthenticated remote nature of the attack vector. The flaw is not listed in the CISA KEV catalog. Attackers can reach the vulnerable component over the network, potentially leveraging it to disrupt service or gain unauthorized code execution without credentials.
OpenCVE Enrichment