Impact
Untrusted remote parties can trigger a denial‑of‑service condition in HPE EdgeConnect SD‑WAN Gateways by submitting malformed requests to the gateway’s management interface, causing the service to become unavailable. The weakness arises from insufficient input validation and uncontrolled resource consumption, leading to interruption of normal operation. This flaw does not compromise confidentiality or integrity but can disrupt network connectivity for all users relying on the gateway.
Affected Systems
The vulnerability targets Hewlett Packard Enterprise’s EdgeConnect SD‑WAN Gateways. No specific firmware or software version is identified in the CVE data, so any unpatched installation of this product line is potentially affected.
Risk and Exploitability
The CVSS score of 5.9 reflects a moderate impact on functionality. The EPSS score of less than 1% indicates a very low, non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is unauthenticated remote access to the gateway’s management interfaces, where an attacker can send crafted traffic that exhausts system resources or crashes the service.
OpenCVE Enrichment