Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CERTFR-2026-AVI-1179
Vulnerability from certfr_avis
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Impacted products
| Vendor | Product | Description | ||
|---|---|---|---|---|
| HPE Aruba Networking | EdgeConnect SD-WAN Gateways | EdgeConnect SD-WAN Gateways versions 9.7.x.x antérieures à ECOS 9.7.1.0 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Orchestrator | EdgeConnect SD-WAN Orchestrator versions 9.7.x antérieures à Orchestrator 9.7.1 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Gateways | EdgeConnect SD-WAN Gateways versions 9.6.x.x antérieures à ECOS 9.6.4.0 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Gateways | EdgeConnect SD-WAN Gateways versions 9.5.x.x antérieures à ECOS 9.5.9.0 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Orchestrator | EdgeConnect SD-WAN Orchestrator versions 9.6.x antérieures à Orchestrator 9.6.4 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Gateways | EdgeConnect SD-WAN Gateways versions 9.4.x.x antérieures à ECOS 9.4.9.0 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Orchestrator | EdgeConnect SD-WAN Orchestrator versions 9.4.x antérieures à Orchestrator 9.4.11 | ||
| HPE Aruba Networking | EdgeConnect SD-WAN Orchestrator | EdgeConnect SD-WAN Orchestrator versions 9.5.x antérieures à Orchestrator 9.5.9 |
References
| Title | Publication Time | Tags | |||
|---|---|---|---|---|---|
|
|||||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [
{
"description": "EdgeConnect SD-WAN Gateways versions 9.7.x.x ant\u00e9rieures \u00e0 ECOS 9.7.1.0",
"product": {
"name": "EdgeConnect SD-WAN Gateways",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Orchestrator versions 9.7.x ant\u00e9rieures \u00e0 Orchestrator 9.7.1",
"product": {
"name": "EdgeConnect SD-WAN Orchestrator",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Gateways versions 9.6.x.x ant\u00e9rieures \u00e0 ECOS 9.6.4.0",
"product": {
"name": "EdgeConnect SD-WAN Gateways",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Gateways versions 9.5.x.x ant\u00e9rieures \u00e0 ECOS 9.5.9.0",
"product": {
"name": "EdgeConnect SD-WAN Gateways",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Orchestrator versions 9.6.x ant\u00e9rieures \u00e0 Orchestrator 9.6.4",
"product": {
"name": "EdgeConnect SD-WAN Orchestrator",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Gateways versions 9.4.x.x ant\u00e9rieures \u00e0 ECOS 9.4.9.0",
"product": {
"name": "EdgeConnect SD-WAN Gateways",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Orchestrator versions 9.4.x ant\u00e9rieures \u00e0 Orchestrator 9.4.11",
"product": {
"name": "EdgeConnect SD-WAN Orchestrator",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
},
{
"description": "EdgeConnect SD-WAN Orchestrator versions 9.5.x ant\u00e9rieures \u00e0 Orchestrator 9.5.9",
"product": {
"name": "EdgeConnect SD-WAN Orchestrator",
"vendor": {
"name": "HPE Aruba Networking",
"scada": false
}
}
}
],
"affected_systems_content": "",
"content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
"cves": [
{
"name": "CVE-2026-76700",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76700"
},
{
"name": "CVE-2026-76702",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76702"
},
{
"name": "CVE-2026-76687",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76687"
},
{
"name": "CVE-2026-76705",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76705"
},
{
"name": "CVE-2026-76693",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76693"
},
{
"name": "CVE-2026-76675",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76675"
},
{
"name": "CVE-2026-76691",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76691"
},
{
"name": "CVE-2026-76684",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76684"
},
{
"name": "CVE-2026-76692",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76692"
},
{
"name": "CVE-2026-76685",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76685"
},
{
"name": "CVE-2026-76695",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76695"
},
{
"name": "CVE-2026-76670",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76670"
},
{
"name": "CVE-2026-76683",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76683"
},
{
"name": "CVE-2026-76678",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76678"
},
{
"name": "CVE-2026-76707",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76707"
},
{
"name": "CVE-2026-76674",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76674"
},
{
"name": "CVE-2026-76669",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76669"
},
{
"name": "CVE-2026-76690",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76690"
},
{
"name": "CVE-2026-76677",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76677"
},
{
"name": "CVE-2026-76703",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76703"
},
{
"name": "CVE-2026-76704",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76704"
},
{
"name": "CVE-2026-76673",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76673"
},
{
"name": "CVE-2024-32664",
"url": "https://www.cve.org/CVERecord?id=CVE-2024-32664"
},
{
"name": "CVE-2026-76698",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76698"
},
{
"name": "CVE-2026-76682",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76682"
},
{
"name": "CVE-2026-76696",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76696"
},
{
"name": "CVE-2026-76689",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76689"
},
{
"name": "CVE-2026-76681",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76681"
},
{
"name": "CVE-2026-76672",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76672"
},
{
"name": "CVE-2026-76706",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76706"
},
{
"name": "CVE-2026-76686",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76686"
},
{
"name": "CVE-2026-76694",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76694"
},
{
"name": "CVE-2026-76688",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76688"
},
{
"name": "CVE-2026-76679",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76679"
},
{
"name": "CVE-2026-76699",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76699"
},
{
"name": "CVE-2026-76701",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76701"
},
{
"name": "CVE-2026-76676",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76676"
},
{
"name": "CVE-2026-76680",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76680"
},
{
"name": "CVE-2026-76697",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-76697"
}
],
"initial_release_date": "2026-09-16T00:00:00",
"last_revision_date": "2026-09-16T00:00:00",
"links": [],
"reference": "CERTFR-2026-AVI-1179",
"revisions": [
{
"description": "Version initiale",
"revision_date": "2026-09-16T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
},
{
"description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
},
{
"description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
},
{
"description": "Contournement de la politique de s\u00e9curit\u00e9"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
},
{
"description": "\u00c9l\u00e9vation de privil\u00e8ges"
}
],
"summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits HPE Aruba Networking. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits HPE Aruba Networking",
"vendor_advisories": [
{
"published_at": "2026-09-15",
"title": "Bulletin de s\u00e9curit\u00e9 HPE Aruba Networking HPESBNW05135",
"url": "https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05135.txt"
}
]
}
CVE-2026-76690 (GCVE-0-2026-76690)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:49.320Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Remote Code Execution Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76690",
"datePublished": "2026-09-15T19:23:49.320Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:49.320Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76701 (GCVE-0-2026-76701)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:58.418Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76701",
"datePublished": "2026-09-15T19:23:58.418Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:23:58.418Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76669 (GCVE-0-2026-76669)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:25
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:25:15.453Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76669",
"datePublished": "2026-09-15T19:23:32.489Z",
"dateReserved": "2026-08-19T16:11:04.542Z",
"dateUpdated": "2026-09-15T19:25:15.453Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76678 (GCVE-0-2026-76678)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:38.640Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76678",
"datePublished": "2026-09-15T19:23:38.640Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:38.640Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76688 (GCVE-0-2026-76688)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:47.687Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76688",
"datePublished": "2026-09-15T19:23:47.687Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:47.687Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76706 (GCVE-0-2026-76706)
Vulnerability from cvelistv5
Published
2026-09-15 19:24
Modified
2026-09-15 19:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76706",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:45:37.548012Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:45:51.195Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:02.588Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76706",
"datePublished": "2026-09-15T19:24:02.588Z",
"dateReserved": "2026-08-19T16:12:27.185Z",
"dateUpdated": "2026-09-15T19:45:51.195Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76696 (GCVE-0-2026-76696)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76696",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:42:04.603113Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:42:23.695Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:54.286Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76696",
"datePublished": "2026-09-15T19:23:54.286Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:42:23.695Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76707 (GCVE-0-2026-76707)
Vulnerability from cvelistv5
Published
2026-09-15 19:24
Modified
2026-09-16 11:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76707",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:43:27.895014Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T11:52:13.783Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:03.456Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76707",
"datePublished": "2026-09-15T19:24:03.456Z",
"dateReserved": "2026-08-19T16:12:27.185Z",
"dateUpdated": "2026-09-16T11:52:13.783Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76676 (GCVE-0-2026-76676)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker\u0027s control are met. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:37.201Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76676",
"datePublished": "2026-09-15T19:23:37.201Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:37.201Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76686 (GCVE-0-2026-76686)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:46.080Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76686",
"datePublished": "2026-09-15T19:23:46.080Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:46.080Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76681 (GCVE-0-2026-76681)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user\u0027s existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:41.297Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76681",
"datePublished": "2026-09-15T19:23:41.297Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:41.297Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76684 (GCVE-0-2026-76684)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:43.963Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator API",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76684",
"datePublished": "2026-09-15T19:23:43.963Z",
"dateReserved": "2026-08-19T16:11:18.068Z",
"dateUpdated": "2026-09-15T19:23:43.963Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76705 (GCVE-0-2026-76705)
Vulnerability from cvelistv5
Published
2026-09-15 19:24
Modified
2026-09-15 19:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76705",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:46:09.134489Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:46:20.202Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:01.710Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76705",
"datePublished": "2026-09-15T19:24:01.710Z",
"dateReserved": "2026-08-19T16:12:27.185Z",
"dateUpdated": "2026-09-15T19:46:20.202Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76699 (GCVE-0-2026-76699)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:56.805Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76699",
"datePublished": "2026-09-15T19:23:56.805Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:23:56.805Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76694 (GCVE-0-2026-76694)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:43
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76694",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:43:14.738616Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:43:35.201Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.6,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:52.648Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Privilege Escalation Vulnerability in the Command Line Interface of HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76694",
"datePublished": "2026-09-15T19:23:52.648Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:43:35.201Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76682 (GCVE-0-2026-76682)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:42.248Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76682",
"datePublished": "2026-09-15T19:23:42.248Z",
"dateReserved": "2026-08-19T16:11:18.068Z",
"dateUpdated": "2026-09-15T19:23:42.248Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76677 (GCVE-0-2026-76677)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:37.869Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authorization Bypass Leading to Privilege Escalation in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76677",
"datePublished": "2026-09-15T19:23:37.869Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:37.869Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76689 (GCVE-0-2026-76689)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:48.495Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76689",
"datePublished": "2026-09-15T19:23:48.495Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:48.495Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76702 (GCVE-0-2026-76702)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 5.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:59.268Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76702",
"datePublished": "2026-09-15T19:23:59.268Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:23:59.268Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76693 (GCVE-0-2026-76693)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76693",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:44:03.598572Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:44:19.308Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:51.782Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76693",
"datePublished": "2026-09-15T19:23:51.782Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:44:19.308Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76673 (GCVE-0-2026-76673)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:34.718Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76673",
"datePublished": "2026-09-15T19:23:34.718Z",
"dateReserved": "2026-08-19T16:11:04.542Z",
"dateUpdated": "2026-09-15T19:23:34.718Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76672 (GCVE-0-2026-76672)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:33.951Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76672",
"datePublished": "2026-09-15T19:23:33.951Z",
"dateReserved": "2026-08-19T16:11:04.542Z",
"dateUpdated": "2026-09-15T19:23:33.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76691 (GCVE-0-2026-76691)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:50.173Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API Endpoint",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76691",
"datePublished": "2026-09-15T19:23:50.173Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:50.173Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-32664 (GCVE-0-2024-32664)
Vulnerability from cvelistv5
Published
2024-05-07 14:57
Modified
2024-08-02 02:13
Severity ?
VLAI Severity ?
EPSS score ?
CWE
Summary
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19. Workarounds include not use rules with `base64_decode` keyword with `bytes` option with value 1, 2 or 5 and for 7.0.x, setting `app-layer.protocols.smtp.mime.body-md5` to false.
References
| URL | Tags | |
|---|---|---|
Impacted products
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:oisf:suricata:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "suricata",
"vendor": "oisf",
"versions": [
{
"lessThanOrEqual": "6.0.18",
"status": "affected",
"version": "6.0.0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:oisf:suricata:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "suricata",
"vendor": "oisf",
"versions": [
{
"lessThanOrEqual": "7.0.4",
"status": "affected",
"version": "7.0.0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-32664",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-07T18:13:57.659920Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:51:44.327Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T02:13:40.336Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7",
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7"
},
{
"name": "https://github.com/OISF/suricata/commit/311002baf288a225f62cf18a90c5fdd294447379",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/OISF/suricata/commit/311002baf288a225f62cf18a90c5fdd294447379"
},
{
"name": "https://github.com/OISF/suricata/commit/d5ffecf11ad2c6fe89265e518f5d7443caf26ba4",
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "https://github.com/OISF/suricata/commit/d5ffecf11ad2c6fe89265e518f5d7443caf26ba4"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "suricata",
"vendor": "OISF",
"versions": [
{
"status": "affected",
"version": "\u003e= 6.0.0, \u003c= 6.0.18"
},
{
"status": "affected",
"version": "\u003e= 7.0.0, \u003c= 7.0.4"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets can cause a limited buffer overflow. This vulnerability is fixed in 7.0.5 and 6.0.19. Workarounds include not use rules with `base64_decode` keyword with `bytes` option with value 1, 2 or 5 and for 7.0.x, setting `app-layer.protocols.smtp.mime.body-md5` to false."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-122",
"description": "CWE-122: Heap-based Buffer Overflow",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120: Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-07T14:57:01.967Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7"
},
{
"name": "https://github.com/OISF/suricata/commit/311002baf288a225f62cf18a90c5fdd294447379",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/OISF/suricata/commit/311002baf288a225f62cf18a90c5fdd294447379"
},
{
"name": "https://github.com/OISF/suricata/commit/d5ffecf11ad2c6fe89265e518f5d7443caf26ba4",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/OISF/suricata/commit/d5ffecf11ad2c6fe89265e518f5d7443caf26ba4"
}
],
"source": {
"advisory": "GHSA-79vh-hpwq-3jh7",
"discovery": "UNKNOWN"
},
"title": "Suricata\u0027s base64 contains an out of bounds write"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2024-32664",
"datePublished": "2024-05-07T14:57:01.967Z",
"dateReserved": "2024-04-16T14:15:26.878Z",
"dateUpdated": "2024-08-02T02:13:40.336Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2026-76704 (GCVE-0-2026-76704)
Vulnerability from cvelistv5
Published
2026-09-15 19:24
Modified
2026-09-15 19:46
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76704",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:46:37.961557Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:46:52.153Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "This vulnerability was reported by m0x_noob to the HPE Networking Bug Bounty program."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim\u0027s browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:00.963Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76704",
"datePublished": "2026-09-15T19:24:00.963Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:46:52.153Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76695 (GCVE-0-2026-76695)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:42
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76695",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:42:45.830889Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-120",
"description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:42:59.417Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:53.462Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76695",
"datePublished": "2026-09-15T19:23:53.462Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:42:59.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76700 (GCVE-0-2026-76700)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:57.617Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76700",
"datePublished": "2026-09-15T19:23:57.617Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:23:57.617Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76670 (GCVE-0-2026-76670)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "This vulnerability was reported by Christopher Alejandro (Moroco) to the HPE Networking Bug Bounty program."
}
],
"descriptions": [
{
"lang": "en",
"value": "Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:33.196Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76670",
"datePublished": "2026-09-15T19:23:33.196Z",
"dateReserved": "2026-08-19T16:11:04.542Z",
"dateUpdated": "2026-09-15T19:23:33.196Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76697 (GCVE-0-2026-76697)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:41
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76697",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:41:25.543570Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:41:37.774Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:55.109Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management Interface",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76697",
"datePublished": "2026-09-15T19:23:55.109Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:41:37.774Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76703 (GCVE-0-2026-76703)
Vulnerability from cvelistv5
Published
2026-09-15 19:24
Modified
2026-09-15 19:24
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:00.096Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes Denial-of-Service",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76703",
"datePublished": "2026-09-15T19:24:00.096Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:24:00.096Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76683 (GCVE-0-2026-76683)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker\u0027s control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:43.117Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76683",
"datePublished": "2026-09-15T19:23:43.117Z",
"dateReserved": "2026-08-19T16:11:18.068Z",
"dateUpdated": "2026-09-15T19:23:43.117Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76692 (GCVE-0-2026-76692)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:44
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76692",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:44:38.671408Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:44:56.218Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:51.041Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76692",
"datePublished": "2026-09-15T19:23:51.041Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:44:56.218Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76680 (GCVE-0-2026-76680)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user\u0027s existing privilege level."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:40.162Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76680",
"datePublished": "2026-09-15T19:23:40.162Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:40.162Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76698 (GCVE-0-2026-76698)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:56.000Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Command Injection Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76698",
"datePublished": "2026-09-15T19:23:56.000Z",
"dateReserved": "2026-08-19T16:12:09.681Z",
"dateUpdated": "2026-09-15T19:23:56.000Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76674 (GCVE-0-2026-76674)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:35.574Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76674",
"datePublished": "2026-09-15T19:23:35.574Z",
"dateReserved": "2026-08-19T16:11:04.542Z",
"dateUpdated": "2026-09-15T19:23:35.574Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76685 (GCVE-0-2026-76685)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer overflow. Successful exploitation could result in a buffer overflow, potentially leading to remote code execution or denial-of-service.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer overflow. Successful exploitation could result in a buffer overflow, potentially leading to remote code execution or denial-of-service."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:44.663Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76685",
"datePublished": "2026-09-15T19:23:44.663Z",
"dateReserved": "2026-08-19T16:11:34.860Z",
"dateUpdated": "2026-09-15T19:23:44.663Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76679 (GCVE-0-2026-76679)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:39.403Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76679",
"datePublished": "2026-09-15T19:23:39.403Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:39.403Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76687 (GCVE-0-2026-76687)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0 ≤ 9.7.0 Version: 9.6.0 ≤ 9.6.3 Version: 9.5.0 ≤ 9.5.8 Version: 9.4.0 ≤ 9.4.10 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0",
"status": "affected",
"version": "9.7.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3",
"status": "affected",
"version": "9.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8",
"status": "affected",
"version": "9.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.10",
"status": "affected",
"version": "9.4.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:46.882Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN Orchestrator",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76687",
"datePublished": "2026-09-15T19:23:46.882Z",
"dateReserved": "2026-08-19T16:11:34.861Z",
"dateUpdated": "2026-09-15T19:23:46.882Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76675 (GCVE-0-2026-76675)
Vulnerability from cvelistv5
Published
2026-09-15 19:23
Modified
2026-09-15 19:23
Severity ?
VLAI Severity ?
EPSS score ?
Summary
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways |
Version: 9.7.0.0 ≤ 9.7.0.0 Version: 9.6.0.0 ≤ 9.6.3.1 Version: 9.5.0.0 ≤ 9.5.8.1 Version: 9.4.0.0 ≤ 9.4.8.2 |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "EdgeConnect SD-WAN Gateways",
"vendor": "Hewlett Packard Enterprise (HPE)",
"versions": [
{
"lessThanOrEqual": "9.7.0.0",
"status": "affected",
"version": "9.7.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.6.3.1",
"status": "affected",
"version": "9.6.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.5.8.1",
"status": "affected",
"version": "9.5.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.4.8.2",
"status": "affected",
"version": "9.4.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Internal security research (HPE Networking)."
}
],
"descriptions": [
{
"lang": "en",
"value": "A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:23:36.368Z",
"orgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"shortName": "hpe"
},
"references": [
{
"url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us\u0026docLocale=en_US"
}
],
"source": {
"advisory": "HPESBNW05135",
"discovery": "INTERNAL"
},
"title": "Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "eb103674-0d28-4225-80f8-39fb86215de0",
"assignerShortName": "hpe",
"cveId": "CVE-2026-76675",
"datePublished": "2026-09-15T19:23:36.368Z",
"dateReserved": "2026-08-19T16:11:18.067Z",
"dateUpdated": "2026-09-15T19:23:36.368Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…