Description
A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An attacker who has authenticated administrative privileges can trigger the overflow, which causes the interface or gateway to become unstable or terminate, resulting in a denial of service. The primary consequence is the interruption of network management functions and potential disruption of network traffic if the gateway is a critical path device. The weakness is a classic buffer overflow, allowing uncontrolled memory write during request handling.

Affected Systems

The affected product is Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific firmware or software version numbers are supplied, so any model or firmware that includes the vulnerable web interface is at risk until a patch is applied.

Risk and Exploitability

The CVSS score of 5.5 places it in the medium severity range; the EPSS score of <1% indicates a very low but non‑zero probability that this vulnerability will be exploited. Because the vulnerability is not listed in CISA’s KEV catalog, there is no current evidence of active exploitation in the wild. Successful exploitation requires authenticated administrative access, which limits the attack surface compared to unauthenticated vulnerabilities but still poses a significant risk for organizations that expose the web interface or do not enforce strict access controls.

Generated by OpenCVE AI on September 21, 2026 at 21:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HPE EdgeConnect firmware security update that fixes the web‑interface buffer overflow (see HPE support reference).
  • Limit administrative access to trusted personnel and enforce strong authentication policies so only legitimate users can log into the management interface.
  • If an immediate patch is not available, disable or isolate the web‑based management interface on production gateways to prevent the overflow from affecting network operation.

Generated by OpenCVE AI on September 21, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
Title Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes Denial-of-Service
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-21T19:51:42.731Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76703

cve-icon Vulnrichment

Updated: 2026-09-21T19:51:38.576Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:54.830

Modified: 2026-09-28T13:49:51.827

Link: CVE-2026-76703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:45:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')