Description
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Integrity and Availability Disruption
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a buffer overflow in the operating system of HPE EdgeConnect SD‑WAN Gateways. An unauthenticated remote attacker can send specially crafted packets that trigger the overflow, potentially altering data or causing a crash. Successful exploitation could compromise the integrity of the service and render it unavailable to legitimate users.

Affected Systems

HPE EdgeConnect SD‑WAN Gateways are affected. Specific product versions are vulnerable until a patch is issued.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated remote connection over the network. Exploitation requires sending crafted packets to the gateway’s underlying service, which could lead to partial or complete service disruption. The lack of a publicly known exploit suggests moderate risk, but the critical nature of SD‑WAN infrastructure warrants prompt attention.

Generated by OpenCVE AI on September 15, 2026 at 23:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software patch released by HPE for EdgeConnect SD‑WAN Gateways as soon as it becomes available.
  • Restrict inbound traffic to the gateway so that only trusted sources can communicate with it, minimizing the attack surface.
  • Enable logging and intrusion detection monitoring on the gateway to detect abnormal packet patterns and alert on possible exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.
Title Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:42:59.417Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76695

cve-icon Vulnrichment

Updated: 2026-09-15T19:42:54.402Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:52.777

Modified: 2026-09-15T20:17:52.777

Link: CVE-2026-76695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T00:00:16Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')