Impact
A flaw in the web‑based management interface allows a remote attacker who has authenticated with a low‑privilege account to read sensitive data. The attacker can retrieve configuration or internal details that could be leveraged to expand access to network services provided by HPE EdgeConnect SD‑WAN Gateways. The key consequence is a breach of confidentiality that may serve as a stepping stone to more serious compromise.
Affected Systems
EdgeConnect SD‑WAN Gateways from Hewlett Packard Enterprise are impacted. No specific firmware or software versions are listed in the advisory, so all deployed gateways potentially require evaluation.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The attack vector is remote, requiring the attacker to authenticate with a low‑privilege user on the web interface. Because the attacker must be authenticated, the risk is contingent on the existence of such accounts and the strength of authentication mechanisms. Organizations should treat this as a moderate risk until a patch is applied.
OpenCVE Enrichment