7.2
CVE-2026-76689
- EPSS 0.85%
- Veröffentlicht 15.09.2026 19:23:48
- Zuletzt bearbeitet 28.09.2026 13:57:38
- Erkennungen
Authenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.4.0 < 9.4.11
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.5.0 < 9.5.9
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.6.0 < 9.6.4
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version 9.7.0
Hpe ≫ Edgeconnect Operating System Version >= 9.4.0.0 < 9.4.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.5.0.0 < 9.5.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.6.0.0 < 9.6.4.0
Hpe ≫ Edgeconnect Operating System Version 9.7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.85% | 0.565 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-121 Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US