Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
Published: 2026-09-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The flaw allows a network neighbor without authentication to read selectively exposed portions of the gateway's memory. By examining the memory contents, an attacker can gain insight into active services, configuration parameters, and workflow logic. This information loss could facilitate future attacks, such as credential reuse or privilege escalation, especially if combined with other known weaknesses. The vulnerability is a classic example of sensitive information exposure (CWE‑200).

Affected Systems

The vulnerability targets Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. Any gateway running firmware that has not been updated to the latest HPE release is susceptible. The advisory does not list specific firmware versions, so all installations remain potentially affected until an official patch is applied.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate confidentiality impact. Attackers need local adjacency to the gateway and do not require authentication, so the vector is network adjacent. An EPSS score of 0.00166, equivalent to less than 1%, indicates a very low but nonzero probability of exploitation. Since the CVE is not listed in the CISA KEV catalog, there is no record of active exploitation yet. Nevertheless, the exposure of memory contents can aid attackers in staging more severe attacks, so it should be treated with caution.

Generated by OpenCVE AI on September 17, 2026 at 06:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review and apply the latest firmware or security patch released by HPE for EdgeConnect SD‑WAN Gateways to close the memory disclosure vulnerability.
  • Reconfigure the Gateways to reside on a dedicated, isolated management subnet that is not connected to adjacent network segments, limiting unauthenticated local access.
  • Disable or restrict any management interfaces that are exposed to adjacent networks, and monitor for anomalous memory access attempts.

Generated by OpenCVE AI on September 17, 2026 at 06:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
Title Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-16T11:52:13.783Z

Reserved: 2026-08-19T16:12:27.185Z

Link: CVE-2026-76707

cve-icon Vulnrichment

Updated: 2026-09-15T19:43:32.499Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:56.483

Modified: 2026-09-16T19:21:55.793

Link: CVE-2026-76707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T07:00:24Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor