Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service leading to system crash and network disruption
Action: Apply patch or mitigate
AI Analysis

Impact

A vulnerability in HPE Networking EdgeConnect SD‑WAN Gateways permits an unauthenticated adjacent attacker to trigger a denial of service by crashing the device. The crash prevents the system from rebooting without manual intervention, causing an extended disruption of network connectivity. This weakness is categorized as CWE‑400, a resource‑management error that directly undermines availability.

Affected Systems

HPE EdgeConnect SD‑WAN Gateways are affected. No specific affected firmware or hardware versions were disclosed, so all deployments of this product should be treated as vulnerable until an official statement clarifies otherwise.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is not widely observed yet. However, the described attack vector requires only network adjacency and no authentication, making it a low‑barrier threat for an attacker with access to the same local network. The impact is complete outage of the gateway, which would propagate to downstream users.

Generated by OpenCVE AI on September 15, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect firmware update or patch released by Hewlett Packard Enterprise when available.
  • Use firewall or ACL rules to restrict network access to the EdgeConnect gateways, allowing connections only from trusted management or core network segments.
  • Monitor gateway logs for unexpected reboot or crash events and set alerting on critical system metrics.
  • Consider implementing redundant gateway paths or a fail‑over topology to reduce service impact if a crash occurs.

Generated by OpenCVE AI on September 15, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Title Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:42:23.695Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76696

cve-icon Vulnrichment

Updated: 2026-09-15T19:42:16.550Z

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:53.290

Modified: 2026-09-15T20:17:53.290

Link: CVE-2026-76696

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption