Impact
A flaw in the operating system of HPE EdgeConnect SD‑WAN Gateways allows an attacker who has local administrative credentials to trigger a denial‑of‑service. The attacker can cause the gateway to become unstable, resulting in halted system operations and temporary loss of network connectivity. The vulnerability does not grant attackers access to confidential data or alter data integrity, but it disrupts the availability of network services that rely on the gateway.
Affected Systems
The impact is limited to Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware versions are listed, so all current installations should be treated as potentially vulnerable until an official firmware update is released by HPE.
Risk and Exploitability
The CVSS base score of 5.8 indicates moderate severity, and the EPSS score of < 1% points to a very low likelihood of exploitation. The vulnerability is not included in CISA’s KEV catalog. The required conditions for exploitation are an authenticated local session; therefore an attacker must first obtain legitimate credentials or access the device locally. Once authenticated, the attacker can use the flaw to induce a service failure, after which manual or automated reboot may be necessary to restore normal operation.
OpenCVE Enrichment