Impact
The vulnerability is a buffer overflow in an API endpoint of HPE EdgeConnect SD‑WAN Gateways. Successful exploitation enables an authenticated attacker with administrative privileges to execute arbitrary commands on the underlying operating system, granting complete control of the gateway.
Affected Systems
All HPE EdgeConnect SD‑WAN Gateways are potentially affected. No specific product or firmware versions are listed, so any gateway that supports the vulnerable API endpoint should be considered at risk.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. The exploit requires remote access and valid administrative credentials, implying that the attacker must have authenticated or compromised admin access. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. Nonetheless, the remote code execution capability could lead to significant damage if leveraged by an attacker with sufficient network access or privileged credentials.
OpenCVE Enrichment