Impact
A flaw in the API endpoint of HPE EdgeConnect SD-WAN Orchestrator enables an unauthenticated attacker to retrieve security‑relevant configuration details and the status of security features. The disclosure of such information constitutes a direct compromise of confidentiality and, because the exposed data can be leveraged to plan further attacks, it poses a potential stepping‑stone for additional compromise.
Affected Systems
The vulnerability affects Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. No specific affected product versions are listed in the advisory; therefore, all current releases are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the issue is not listed in CISA KEV, suggesting no known active exploitation. The attack vector is inferred to be remote through the exposed API, requiring no authentication. Because the vulnerability is unauthenticated and can be accessed by anyone who can reach the API, the risk is significant if the API is openly exposed. With proper network segmentation or inspection, the practical exploitation difficulty increases.
OpenCVE Enrichment