6.6
CVE-2026-76694
- EPSS 0.42%
- Veröffentlicht 15.09.2026 19:23:52
- Zuletzt bearbeitet 28.09.2026 13:47:46
- Erkennungen
Authenticated Privilege Escalation Vulnerability in the Command Line Interface of HPE Networking EdgeConnect SD-WAN Gateways
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.4.0 < 9.4.11
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.5.0 < 9.5.9
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.6.0 < 9.6.4
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version 9.7.0
Hpe ≫ Edgeconnect Operating System Version >= 9.4.0.0 < 9.4.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.5.0.0 < 9.5.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.6.0.0 < 9.6.4.0
Hpe ≫ Edgeconnect Operating System Version 9.7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.357 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US