Impact
The vulnerability allows an authenticated local attacker to trigger a denial‑of‑service on HPE EdgeConnect SD‑WAN Gateways, causing system operations to halt and the device to become unstable. This disrupts network functions but does not directly compromise data confidentiality or integrity.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. No specific firmware version range is provided, so all current installations should be treated as vulnerable until an official update is available.
Risk and Exploitability
The CVSS base score of 5.8 indicates a moderate severity exploit that requires local administrative access. EPSS is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. Nevertheless, an attacker who gains local credentials could disrupt network services, affecting business continuity. It is therefore prudent to remediate promptly.
OpenCVE Enrichment