Impact
The flaw enables an authenticated remote attacker who already holds a high‑privilege account on an HPE EdgeConnect SD‑WAN Gateway to raise their privileges beyond the authorized level and run arbitrary code. This can lead to full compromise of the device, threatening confidentiality, integrity, and availability of the network services it controls.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The vulnerability affects all product instances that expose the command‑line interface to authenticated users; specific firmware versions are not disclosed.
Risk and Exploitability
The CVSS score of 6.6 reflects a moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exfiltration requires remote authentication with a high‑privilege account; once privilege is escalated, the attacker can execute arbitrary commands on the device.
OpenCVE Enrichment