Description
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

Untrusted remote parties can trigger a denial‑of‑service condition in HPE EdgeConnect SD‑WAN Gateways by submitting malformed requests to the gateway’s management interface, causing the service to become unavailable. The weakness arises from insufficient input validation and uncontrolled resource consumption, leading to interruption of normal operation. This flaw does not compromise confidentiality or integrity but can disrupt network connectivity for all users relying on the gateway.

Affected Systems

The vulnerability targets Hewlett Packard Enterprise’s EdgeConnect SD‑WAN Gateways. No specific firmware or software version is identified in the CVE data, so any unpatched installation of this product line is potentially affected.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate impact on functionality. The EPSS score of less than 1% indicates a very low, non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is unauthenticated remote access to the gateway’s management interfaces, where an attacker can send crafted traffic that exhausts system resources or crashes the service.

Generated by OpenCVE AI on September 22, 2026 at 23:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by HPE that addresses the DoS vulnerability
  • Restrict remote access to the SD‑WAN gateway by configuring the firewall to allow only trusted IP ranges
  • Monitor gateway logs and performance metrics for signs of resource exhaustion or repeated failover events

Generated by OpenCVE AI on September 22, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Tue, 22 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-399

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-399

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Title Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-22T18:20:38.959Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76700

cve-icon Vulnrichment

Updated: 2026-09-22T18:19:52.211Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:54.507

Modified: 2026-09-28T13:52:35.027

Link: CVE-2026-76700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T23:45:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption