Impact
A flaw in HPE EdgeConnect SD‑WAN Gateways allows an unauthenticated attacker that is adjacent to read uninitialized stack memory and to crash the gateway service. The information disclosure is limited to a small fragment of memory, while the crash can cause a full system restart, disrupting all SD‑WAN operations for affected users.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific version information is listed, so all current releases should be considered potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a moderate to high risk. EPSS data is not available, and the issue is catalog. Attackers would need to be on a physically adjacent or otherwise trusted network segment to exploit the flaw, so the primary vector is local network proximity rather than remote access.
OpenCVE Enrichment