Impact
A limited buffer overflow exists in the network security monitoring component of HPE EdgeConnect's intrusion detection system. The flaw arises from missing or inadequate bounds checking when processing externally supplied data, allowing an unauthenticated user to corrupt memory and trigger a denial-of-service or, in some cases, execute arbitrary code on the gateway.
Affected Systems
All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateway installations are potentially affected; the vulnerability description does not specify individual firmware or build numbers, so administrators should verify that no patch addressing this buffer overflow exists in their deployed firmware.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. However, the defect is reachable over the network from any remote, unauthenticated host and is not listed in the CISA KEV catalog, meaning no public exploits are known but the risk remains high due to the potential for service disruption or code execution.
OpenCVE Enrichment