Executive brief
HPE IceWall Federation Agent and Proxy are security components used to manage federated authentication and access control in enterprise environments. A remote, unauthenticated attacker can exploit a vulnerability to cause a denial of service, rendering these authentication systems unavailable and disrupting user access to protected applications.
Technical details
A remote denial of service vulnerability exists in HPE IceWall Federation Agent and Proxy that can be triggered by an unauthenticated attacker over the network. The vulnerability does not require authentication or user interaction. A successful exploit allows an attacker to crash or hang the affected service, causing availability impact to the federation infrastructure. Patch availability is indicated by the HPE advisory URL, suggesting mitigation is available through official updates.
Affected products
- HPE IceWall Federation Agent <UNKNOWN>
- HPE IceWall Federation Proxy <UNKNOWN>
Timeline
- 2026-09-11: disclosed