Impact
A vulnerability in HPE Networking EdgeConnect SD‑WAN Gateways permits an unauthenticated adjacent attacker to trigger a denial of service by crashing the device. The crash prevents the system from rebooting without manual intervention, causing an extended disruption of network connectivity. This weakness is categorized as CWE‑400, a resource‑management error that directly undermines availability.
Affected Systems
HPE EdgeConnect SD‑WAN Gateways are affected. No specific affected firmware or hardware versions were disclosed, so all deployments of this product should be treated as vulnerable until an official statement clarifies otherwise.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is not widely observed yet. However, the described attack vector requires only network adjacency and no authentication, making it a low‑barrier threat for an attacker with access to the same local network. The impact is complete outage of the gateway, which would propagate to downstream users.
OpenCVE Enrichment