Description
A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Published: 2026-09-15
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated local attacker to trigger a denial‑of‑service on HPE EdgeConnect SD‑WAN Gateways, causing system operations to halt and the device to become unstable. This disrupts network functions but does not directly compromise data confidentiality or integrity.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. No specific firmware version range is provided, so all current installations should be treated as vulnerable until an official update is available.

Risk and Exploitability

The CVSS base score of 5.8 indicates a moderate severity exploit that requires local administrative access. EPSS is < 1%, indicating a low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. Nevertheless, an attacker who gains local credentials could disrupt network services, affecting business continuity. It is therefore prudent to remediate promptly.

Generated by OpenCVE AI on September 17, 2026 at 06:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that addresses the denial‑of‑service flaw
  • Remove or lock unnecessary local administrative accounts to reduce the attack surface
  • Enable logging and continuous monitoring for signs of abnormal service termination or restarts

Generated by OpenCVE AI on September 17, 2026 at 06:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Title Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:23:59.268Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:54.720

Modified: 2026-09-16T19:20:52.817

Link: CVE-2026-76702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:00:24Z

Weaknesses

No weakness.