Description
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
Published: 2026-09-15
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

A buffer overflow exists in a system service of the operating system that runs on HPE Networking EdgeConnect SD‑WAN Gateways. If a sufficiently privileged attacker who can send traffic adjacent to the gateway can exploit the overflow, the vulnerable service can crash, leading to a temporary service interruption and degraded network operations. The flaw is an uncontrolled memory write and does not allow direct code execution but can impact confidentiality or integrity only indirectly by disrupting service availability.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The vulnerability is present in the underlying operating system of the gateway; no specific firmware or OS version numbers are listed but all models listed in the vendor’s advisory are affected.

Risk and Exploitability

The CVSS score of 6.4 classifies this issue as a medium severity denial‑of‑service fault. The EPSS score is not available, so no specific exploitation probability is measured, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the same local network segment, inferred from the advisory wording that the attack does not require authentication but does rely on lateral proximity. Exploitation requires the attacker to inject malformed packets or data that trigger the overflow of the vulnerable service; no user interaction is required beyond network presence.

Generated by OpenCVE AI on September 15, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to a firmware revision that contains the vendor’s patch once it is released.
  • If a patch is not immediately available, stop or disable the vulnerable service to prevent crashes.
  • Segment the network so that only trusted devices can reach the gateway; restrict adjacent access via VLANs or ACLs.
  • Monitor the gateway for service restarts or high CPU usage as an indicator of potential exploitation.

Generated by OpenCVE AI on September 15, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
Title Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:56.805Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-15T20:17:54.397

Modified: 2026-09-15T20:17:54.397

Link: CVE-2026-76699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:30:07Z

Weaknesses

No weakness.