Impact
The EdgeConnect SD‑WAN Orchestrator web interface contains a flaw that lets an unauthenticated remote actor circumvent its authentication checks. If successfully exploited, the attacker obtains administrative privileges on the Orchestrator host, granting full control to modify network policies, intercept traffic, and tamper with secure communication. This breach of confidentiality, integrity, and availability could compromise the entire SD‑WAN deployment.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. All currently released firmware versions are potentially impacted, as no specific version is excluded in the advisory. The advisory recommends applying the latest patch as soon as it becomes available.
Risk and Exploitability
With a CVSS score of 7.5, the issue is classified as high severity. The EPSS score is below 1 %, indicating a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would exploit the public web interface, sending crafted HTTP requests to bypass login and elevate privileges. Given the high level of access granted, the risk of complete compromise remains significant.
OpenCVE Enrichment