Executive brief
HPE EdgeConnect SD-WAN Gateways are network appliances used to optimize and secure wide-area network traffic. An unauthenticated attacker on the same network segment can read portions of system memory, potentially exposing internal service details and configuration data that could be chained with other attacks to gain unauthorized access or elevated privileges.
Technical details
This is an information disclosure vulnerability in HPE EdgeConnect SD-WAN Gateways that allows an unauthenticated adjacent attacker to read arbitrary system memory contents. The vulnerability requires network adjacency (same local network segment) but no authentication. Successful exploitation leaks sensitive data about internal services and workflows, which can be leveraged in multi-stage attacks to escalate privileges or gain unauthorized access. The attack combines memory disclosure with other vulnerabilities to achieve meaningful impact. A patch is available from HPE.
Affected products
- HPE EdgeConnect SD-WAN Gateway
Timeline
- 2026-09-15: disclosed