Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service leading to system crash and network disruption
Action: Apply patch or mitigate
AI Analysis

Impact

A vulnerability in HPE Networking EdgeConnect SD‑WAN Gateways permits an unauthenticated adjacent attacker to trigger a denial of service by crashing the device. The crash prevents the system from rebooting without manual intervention, causing an extended disruption of network connectivity. This weakness is categorized as CWE‑400, a resource‑management error that directly undermines availability.

Affected Systems

HPE EdgeConnect SD‑WAN Gateways are affected. No specific affected firmware or hardware versions were disclosed, so all deployments of this product should be treated as vulnerable until an official statement clarifies otherwise.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is not widely observed yet. However, the described attack vector requires only network adjacency and no authentication, making it a low‑barrier threat for an attacker with access to the same local network. The impact is complete outage of the gateway, which would propagate to downstream users.

Generated by OpenCVE AI on September 20, 2026 at 11:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect firmware update or patch released by Hewlett Packard Enterprise when available.
  • Use firewall or ACL rules to restrict network access to the EdgeConnect gateways, allowing connections only from trusted management or core network segments.
  • Monitor gateway logs for unexpected reboot or crash events and set alerting on critical system metrics.
  • Consider implementing redundant gateway paths or a fail‑over topology to reduce service impact if a crash occurs.

Generated by OpenCVE AI on September 20, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Title Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:42:23.695Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76696

cve-icon Vulnrichment

Updated: 2026-09-15T19:42:16.550Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:53.290

Modified: 2026-09-28T13:47:54.913

Link: CVE-2026-76696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:00:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption