Impact
A buffer overflow exists in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An attacker who has authenticated administrative privileges can trigger the overflow, which causes the interface or gateway to become unstable or terminate, resulting in a denial of service. The primary consequence is the interruption of network management functions and potential disruption of network traffic if the gateway is a critical path device. The weakness is a classic buffer overflow, allowing uncontrolled memory write during request handling.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or software version numbers are supplied, so any model or firmware that includes the vulnerable web interface is at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 places it in the medium severity range; the EPSS score is not available, so the likelihood of exploitation is undetermined but potentially low to moderate. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploit in the wild. Successful exploitation requires authenticated administrative access, which reduces the attack surface compared to unauthenticated vulnerabilities but still represents a significant risk for organizations that keep the web interface exposed or do not enforce strict access controls.
OpenCVE Enrichment