Description
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
Published: 2026-09-15
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

A buffer overflow exists in a system service of the operating system that runs on Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The overflow is an uncontrolled memory write that can crash the vulnerable service and temporarily interrupt network operations. The flaw does not allow code execution or direct manipulation of data; it is limited to availability impact only.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. It resides in the underlying operating system of these gateways; no specific firmware or operating system version numbers are listed, and all models referenced in the vendor’s advisory are considered affected.

Risk and Exploitability

The CVSS score of 6.4 classifies this as a medium severity denial‑of‑service issue. The EPSS score is < 1%, indicating a very low probability of exploitation in the current marketplace, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the same local network segment, inferred from the advisory wording that the attack does not require authentication but relies on local proximity. Exploitation requires the attacker to send malformed packets or data that trigger the overflow; no user interaction beyond network presence is required.

Generated by OpenCVE AI on September 22, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE firmware update that contains the vendor’s patch for the buffer overflow.
  • If a patch is not yet available, stop or disable the susceptible system service to prevent repeat crashes.
  • Restrict network access to the gateway so that only trusted devices on the same local segment can communicate with it; use VLANs or ACLs.
  • Continuously monitor the gateway for service restarts, abnormal CPU usage, or signs of exploitation to enable rapid response.

Generated by OpenCVE AI on September 22, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Tue, 22 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sun, 20 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
Title Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-22T18:19:03.091Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76699

cve-icon Vulnrichment

Updated: 2026-09-22T18:17:59.499Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:54.397

Modified: 2026-09-28T13:52:31.020

Link: CVE-2026-76699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T23:45:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')