7.1

CVE-2026-76692

Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.4.0 < 9.4.11
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.5.0 < 9.5.9
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.6.0 < 9.6.4
Hpe ≫ Edgeconnect Operating System Version >= 9.4.0.0 < 9.4.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.5.0.0 < 9.5.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.6.0.0 < 9.6.4.0
Hpe ≫ Edgeconnect Operating System Version 9.7.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.09
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HPE 7.1 2.8 4.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
Vendor Advisory