Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Published: 2026-09-15
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service and Limited Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

A flaw in HPE EdgeConnect SD‑WAN Gateways allows an unauthenticated attacker that is adjacent to read uninitialized stack memory and to crash the gateway service. The information disclosure is limited to a small fragment of memory, while the crash can cause a full system restart, disrupting all SD‑WAN operations for affected users.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific version information is listed, so all current releases should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating a moderate to high risk. EPSS data is not available, and the issue is catalog. Attackers would need to be on a physically adjacent or otherwise trusted network segment to exploit the flaw, so the primary vector is local network proximity rather than remote access.

Generated by OpenCVE AI on September 15, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by HPE that addresses the memory disclosure and denial‑of‑service issue.
  • Restrict physical and network access to the gateway by enforcing VLAN segmentation, port‑based authentication, or MAC filtering to block unauthenticated adjacent hosts.
  • Deploy monitoring to detect unexpected restarts or abnormal memory usage and configure alerts to notify administrators of potential exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Title Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:44:56.218Z

Reserved: 2026-08-19T16:11:34.861Z

Link: CVE-2026-76692

cve-icon Vulnrichment

Updated: 2026-09-15T19:44:52.904Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:51.263

Modified: 2026-09-15T20:17:51.263

Link: CVE-2026-76692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T00:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor