Impact
The flaw resides in the operating system of HPE EdgeConnect SD‑WAN gateways, allowing an unauthenticated attacker to trigger a denial‑of‑service condition. The primary consequence is the loss of service availability for the gateway, potentially disrupting the WAN connections of all downstream endpoints that rely on it. Confidentiality and integrity appear unaffected, as the exploitation does not grant credential or data access, but the availability loss could cause significant business downtime.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN gateways are impacted. No specific firmware or OS version is listed; the issue applies generically to the underlying OS used by these gateways.
Risk and Exploitability
The CVSS v3 score of 7.5 classifies the vulnerability as high severity, while the EPSS score is not available and the weakness is not present in the CISA KEV catalog. This suggests that, although the exploitation vector typically involves network‑based traffic toward the gateway, there is no public evidence of widespread exploitation as of now. Nonetheless, an attacker can potentially send crafted packets or requests that exhaust gateway resources, forcing the service to become unresponsive. The lack of authentication requirements and the disclosed high severity underscore the need for timely remediation.
OpenCVE Enrichment