Impact
The vulnerability is a buffer overflow in the operating system of HPE EdgeConnect SD‑WAN Gateways. An unauthenticated remote attacker can send specially crafted packets that trigger the overflow, potentially altering data or causing a crash. Successful exploitation could compromise the integrity of the service and render it unavailable to legitimate users.
Affected Systems
HPE EdgeConnect SD‑WAN Gateways are affected. Specific product versions are vulnerable until a patch is issued.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated remote connection over the network. Exploitation requires sending crafted packets to the gateway’s underlying service, which could lead to partial or complete service disruption. The lack of a publicly known exploit suggests moderate risk, but the critical nature of SD‑WAN infrastructure warrants prompt attention.
OpenCVE Enrichment