Executive brief
HPE EdgeConnect SD-WAN Gateways are networking appliances used to manage and secure wide-area network (WAN) traffic for enterprise branches. A buffer overflow vulnerability in the underlying operating system's system service could allow a nearby attacker to crash the gateway, temporarily disrupting network connectivity and business operations without needing to authenticate first.
Technical details
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE EdgeConnect SD-WAN Gateways. The vulnerability can be triggered by an unauthenticated adjacent attacker (no authentication required, but attacker must be on the same network segment). Successful exploitation allows an attacker to crash the affected service, causing a denial-of-service condition that temporarily disrupts network operations. The attack vector is adjacent network access, and the primary impact is availability degradation.
Affected products
- HPE EdgeConnect SD-WAN Gateway
Timeline
- 2026-09-15: disclosed