Impact
Buffer overflow vulnerabilities were found in the API endpoint of HPE Networking EdgeConnect SD‑WAN Gateways. An attacker who has authenticated access can trigger a memory corruption that allows the execution of arbitrary commands with the privileges of the underlying operating system. The impact is a full compromise of the device’s confidentiality, integrity, and availability, potentially enabling a network takeover.
Affected Systems
Since no specific version information is provided, all deployed EdgeConnect SD‑WAN Gateways that expose the vulnerable API endpoint may be at risk. Version details are not disclosed.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level. The EPSS score is very low at less than 1%, suggesting that the likelihood of exploitation is low, and it is not listed in CISA's KEV catalogue. Attackers would need valid credentials and access to the API interface; successful exploitation could enable remote code execution as a privileged operating system user.
OpenCVE Enrichment