Description
A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An attacker who has authenticated administrative privileges can trigger the overflow, which causes the interface or gateway to become unstable or terminate, resulting in a denial of service. The primary consequence is the interruption of network management functions and potential disruption of network traffic if the gateway is a critical path device. The weakness is a classic buffer overflow, allowing uncontrolled memory write during request handling.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or software version numbers are supplied, so any model or firmware that includes the vulnerable web interface is at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 5.5 places it in the medium severity range; the EPSS score is not available, so the likelihood of exploitation is undetermined but potentially low to moderate. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploit in the wild. Successful exploitation requires authenticated administrative access, which reduces the attack surface compared to unauthenticated vulnerabilities but still represents a significant risk for organizations that keep the web interface exposed or do not enforce strict access controls.

Generated by OpenCVE AI on September 15, 2026 at 23:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect firmware security update that fixes the web‑interface buffer overflow (see HPE support reference).
  • Limit administrative access to trusted personnel and enforce strong authentication policies so only legitimate users can log into the management interface.
  • If an immediate patch is not available, disable or isolate the web‑based management interface on production gateways to prevent the overflow from affecting network operation.

Generated by OpenCVE AI on September 15, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Title Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes Denial-of-Service
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-15T19:24:00.096Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:54.830

Modified: 2026-09-16T19:20:52.817

Link: CVE-2026-76703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:30:07Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')