Impact
The vulnerability resides in the web-based management interface of the EdgeConnect SD‑WAN Orchestrator and could potentially allow an unauthenticated remote actor to bypass existing authentication controls. By successfully exploiting this flaw, an attacker can obtain administrative privileges, enabling full compromise of the Orchestrator host. This provides an attacker with the ability to alter network policies, access sensitive data, and potentially affect the entire SD‑WAN deployment.
Affected Systems
The flaw affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. Specific version information is not provided in the advisory, implying that all current releases are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as high severity. The EPSS probability of exploitation at the moment, but the nature of the vulnerability—remote authentication bypass resulting in administrative control—places it listed but the attack vector is likely through the publicly reachable web interface, meaning an attacker could send crafted HTTP requests to circumvent login checks and elevate privileges.
OpenCVE Enrichment