Impact
A stored cross‑site scripting flaw resides in the EdgeConnect SD‑WAN Orchestrator's web‑based management interface. An attacker who authenticates to the system can submit malicious script that is persisted and later executed in a victim’s browser while the browser is logged into the interface. When executed, the script runs with the same privileges as the victim user, enabling collection of sensitive information, tampering with data, or further lateral movement within the network. The weakness is a classic input validation flaw labeled CWE‑79.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific affected versions are disclosed in the data provided.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5, indicating moderate severity, and has no EPSS score or listing in the CISA KEV catalog. Exploitation requires the attacker to possess valid credentials for the management interface, but once authenticated the attacker can abuse the stored XSS to compromise confidentiality and integrity for that user’s session. Because the attack vector is authenticated remote and the exploit can run arbitrary browser code, the risk to organizations operating EdgeConnect is tangible but not catastrophic without additional weaknesses.
OpenCVE Enrichment