Impact
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways allows an unauthenticated remote attacker to retrieve sensitive information. This information could be used to potentially gain further access to network services supported by the device.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways. No specific firmware versions are listed in the advisory, so the impact is presumed to apply to all releases known to the vendor that expose the vulnerable API.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability. The disclosure is not tracked in the CISA KEV catalog. The attack vector is remote via the vulnerable API endpoint and requires no authentication; the attacker could use the accessed information to pursue further attacks against the network infrastructure.
OpenCVE Enrichment