Impact
The vulnerability is an integer overflow in the proxy packet processing logic of the EdgeConnect SD‑WAN gateway. When the gateway receives malformed or truncated input, the overflow leads to a buffer overflow condition. Successful exploitation allows a remote attacker to execute arbitrary code or crash the device, resulting in loss of confidentiality, integrity, or availability.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. Version information is not specified in the advisory.
Risk and Exploitability
The CVSS score of 8.1 indicates a high likelihood of significant impact. No EPSS score is available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated remote attacker sending specially crafted packets to the gateway over the network, a scenario that is realistic for transit or edge devices exposed to untrusted traffic.
OpenCVE Enrichment