Impact
A buffer overflow exists in the API endpoint of HPE EdgeConnect SD‑WAN Gateways. The flaw can be triggered by an unauthenticated remote attacker if certain preconditions outside the attacker’s control are met, allowing the execution of arbitrary commands on the underlying host operating system. Successful exploitation would result in full system compromise, giving the attacker complete control over the device.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware version range was supplied, so all releases prior to the vendor's fix are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalogue, so there is no published evidence of active exploitation. However, because the attack vector is remote and unauthenticated, any host that can reach the exposed API endpoint is at risk once the necessary preconditions are satisfied. The low EPSS score does not diminish the potential danger; an attacker who can satisfy the preconditions can achieve remote code execution.
OpenCVE Enrichment