Impact
The identified vulnerability allows an unauthenticated remote attacker to trigger a denial‑of‑service condition in HPE Networking EdgeConnect SD‑WAN Gateways. The flaw can be exploited to interrupt the normal operation of the affected service, potentially leading to network connectivity losses for all users relying on the gateway. No compromise of confidentiality or integrity is claimed, but the disruption could affect business availability and operational continuity.
Affected Systems
The weakness targets Hewlett Packard Enterprise’s EdgeConnect SD‑WAN Gateways, a set of network appliances used for software‑defined wide area networking. No specific firmware or software version details are provided in the CVE data, and the impact applies to all installations of this product line that have not applied the vendor’s fix.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate impact on functionality. The EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is unauthenticated remote access to the gateway’s management interfaces, enabling an attacker to send malformed requests that exhaust or crash the service. The attack does not require privileged credentials or insider access, which increases its practical threat.
OpenCVE Enrichment