Impact
The flaw is a command injection vulnerability (CWE‑77) in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An authenticated remote attacker with limited privileges can send specially crafted input that is not correctly sanitized, allowing the attacker to execute arbitrary system commands with elevated privileges or trigger a denial‑of‑service condition on the affected appliance.
Affected Systems
All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways that expose the web‑based management interface may be affected. No specific product version information was supplied, so the vulnerability may affect any current or future release until patched.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS estimate of 4%, indicating moderate severity but a relatively low probability of exploitation in the field. It is not listed in the CISA KEV catalog, suggesting no publicly demonstrated attacks yet. The likely attack vector is the HTTP or HTTPS management interface, where an authenticated attacker with a limited privileged account can inject malicious commands. If successful, the attacker could disrupt services or gain elevated privileges. Based on the description, it is inferred that the degree of privilege escalation depends on how the application isolates user input from system calls.
OpenCVE Enrichment