Impact
A vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD‑WAN Gateways that allows an unauthenticated remote attacker to retrieve sensitive information. The exposed data could contain configuration details or credentials that may be leveraged to further compromise network services supported by the device.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware versions are listed in the advisory, so the impact is presumed to apply to all releases known to the vendor that expose the vulnerable API.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The disclosure is not tracked in the CISA KEV catalog. The likely attack vector is remote, requiring no authentication, and an attacker could use the gained information to pursue further attacks against the network infrastructure.
OpenCVE Enrichment