5.5
CVE-2026-76705
- EPSS 0.54%
- Veröffentlicht 15.09.2026 19:24:01
- Zuletzt bearbeitet 28.09.2026 13:48:38
- Erkennungen
Authenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.4.0 < 9.4.11
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.5.0 < 9.5.9
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.6.0 < 9.6.4
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version 9.7.0
Hpe ≫ Edgeconnect Operating System Version >= 9.4.0.0 < 9.4.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.5.0.0 < 9.5.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.6.0.0 < 9.6.4.0
Hpe ≫ Edgeconnect Operating System Version 9.7.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.442 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HPE | 5.5 | 1.2 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US