Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and Limited Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A flaw in HPE EdgeConnect SD‑WAN Gateways allows an unauthenticated attacker that is adjacent to read uninitialized stack memory and to crash the gateway service. The information disclosure is limited to a small fragment of memory, while the crash can cause a full system restart, disrupting all SD‑WAN operations for affected users.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific version information is listed, so all current releases should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a moderate to high risk. The EPSS score is < 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in CISA KEV catalog. Attackers would need to be on a physically adjacent or otherwise trusted network segment to exploit the flaw, so the primary vector is local network proximity rather than remote access.

Generated by OpenCVE AI on September 20, 2026 at 12:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by HPE that addresses the memory disclosure and denial‑of‑service issue.
  • Restrict physical and network access to the gateway by enforcing VLAN segmentation, port‑based authentication, or MAC filtering to block unauthenticated adjacent hosts.
  • Deploy monitoring to detect unexpected restarts or abnormal memory usage and configure alerts to notify administrators of potential exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Title Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:44:56.218Z

Reserved: 2026-08-19T16:11:34.861Z

Link: CVE-2026-76692

cve-icon Vulnrichment

Updated: 2026-09-15T19:44:52.904Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:51.263

Modified: 2026-09-28T13:47:38.467

Link: CVE-2026-76692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:15:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor