Impact
A buffer overflow exists in a system service of the operating system that runs on HPE Networking EdgeConnect SD‑WAN Gateways. If a sufficiently privileged attacker who can send traffic adjacent to the gateway can exploit the overflow, the vulnerable service can crash, leading to a temporary service interruption and degraded network operations. The flaw is an uncontrolled memory write and does not allow direct code execution but can impact confidentiality or integrity only indirectly by disrupting service availability.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. The vulnerability is present in the underlying operating system of the gateway; no specific firmware or OS version numbers are listed but all models listed in the vendor’s advisory are affected.
Risk and Exploitability
The CVSS score of 6.4 classifies this issue as a medium severity denial‑of‑service fault. The EPSS score is not available, so no specific exploitation probability is measured, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the same local network segment, inferred from the advisory wording that the attack does not require authentication but does rely on lateral proximity. Exploitation requires the attacker to inject malformed packets or data that trigger the overflow of the vulnerable service; no user interaction is required beyond network presence.
OpenCVE Enrichment