Executive brief
HPE EdgeConnect is a SD-WAN gateway used to optimize and secure branch network traffic. An unauthenticated attacker on an adjacent network can trigger a crash or leak uninitialized memory from the device, disrupting network operations and potentially exposing sensitive data.
Technical details
This vulnerability allows an unauthenticated, adjacent network attacker to obtain limited information from memory and cause denial of service in HPE EdgeConnect SD-WAN Gateways. The attack exploits an uninitialized memory disclosure or memory handling issue accessible without authentication, requiring only network adjacency. Successful exploitation results in either a system crash (DoS) or disclosure of uninitialized stack memory containing sensitive information. No patch information is currently known to be available.
Affected products
- HPE EdgeConnect SD-WAN Gateway <UNKNOWN>
Timeline
- 2026-09-15: disclosed