Impact
The flaw is a command injection vulnerability in the web-based management interface of HPE Networking. An authenticated remote attacker who possesses limited user privileges can send specially crafted input that is not correctly sanitized, allowing the attacker to execute arbitrary system a denial‑of‑service condition or other impacts stemming from elevated privileges.
Affected Systems
All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways that expose are or software versions are yet applied a patch may be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS estimate of 4%, indicating a moderate severity but a relatively low probability of exploitation in the field. It is not listed in the CISA KEV catalog, suggesting no publicly demonstrated attacks yet. The likely attack vector is the HTTP or HTTPS management interface, where an authenticated attacker with a limited privileged account can inject malicious commands. If successful, the attacker could disrupt services or gain elevated privileges. Based on the description, it is inferred that the degree of privilege escalation depends on how the application isolates user input from system calls.
OpenCVE Enrichment