Impact
A buffer overflow exists in a system service of the operating system that runs on Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The overflow is an uncontrolled memory write that can crash the vulnerable service and temporarily interrupt network operations. The flaw does not allow code execution or direct manipulation of data; it is limited to availability impact only.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. It resides in the underlying operating system of these gateways; no specific firmware or operating system version numbers are listed, and all models referenced in the vendor’s advisory are considered affected.
Risk and Exploitability
The CVSS score of 6.4 classifies this as a medium severity denial‑of‑service issue. The EPSS score is < 1%, indicating a very low probability of exploitation in the current marketplace, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the same local network segment, inferred from the advisory wording that the attack does not require authentication but relies on local proximity. Exploitation requires the attacker to send malformed packets or data that trigger the overflow; no user interaction beyond network presence is required.
OpenCVE Enrichment