Impact
A buffer overflow exists in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An attacker who has authenticated administrative privileges can trigger the overflow, which causes the interface or gateway to become unstable or terminate, resulting in a denial of service. The primary consequence is the interruption of network management functions and potential disruption of network traffic if the gateway is a critical path device. The weakness is a classic buffer overflow, allowing uncontrolled memory write during request handling.
Affected Systems
The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or software version numbers are supplied, so any model or firmware that includes the vulnerable web interface is at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 places it in the medium severity range; the EPSS score of <1% indicates a very low but non‑zero probability that this vulnerability will be exploited. Because the vulnerability is not listed in CISA’s KEV catalog, there is no current evidence of active exploitation in the wild. Successful exploitation requires authenticated administrative access, which limits the attack surface compared to unauthenticated vulnerabilities but still poses a significant risk for organizations that expose the web interface or do not enforce strict access controls.
OpenCVE Enrichment