Description
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Published: 2026-09-15
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The identified vulnerability allows an unauthenticated remote attacker to trigger a denial‑of‑service condition in HPE Networking EdgeConnect SD‑WAN Gateways. The flaw can be exploited to interrupt the normal operation of the affected service, potentially leading to network connectivity losses for all users relying on the gateway. No compromise of confidentiality or integrity is claimed, but the disruption could affect business availability and operational continuity.

Affected Systems

The weakness targets Hewlett Packard Enterprise’s EdgeConnect SD‑WAN Gateways, a set of network appliances used for software‑defined wide area networking. No specific firmware or software version details are provided in the CVE data, and the impact applies to all installations of this product line that have not applied the vendor’s fix.

Risk and Exploitability

The CVSS score is 5.9, indicating a moderate impact on functionality. The EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is unauthenticated remote access to the gateway’s management interfaces, enabling an attacker to send malformed requests that exhaust or crash the service. The attack does not require privileged credentials or insider access, which increases its practical threat.

Generated by OpenCVE AI on September 17, 2026 at 07:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or patch released by HPE that addresses the DoS vulnerability
  • Restrict remote access to the SD‑WAN gateway by configuring the firewall to allow only trusted IP ranges
  • Monitor gateway logs and performance metrics for signs of resource exhaustion or repeated failover events

Generated by OpenCVE AI on September 17, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Title Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:57.617Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76700

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:54.507

Modified: 2026-09-16T19:20:52.817

Link: CVE-2026-76700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:52:39Z

Weaknesses

No weakness.