5.3

CVE-2026-76706

Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.4.0 < 9.4.11
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.5.0 < 9.5.9
Arubanetworks ≫ Edgeconnect Sd-wan Orchestrator Version >= 9.6.0 < 9.6.4
Hpe ≫ Edgeconnect Operating System Version >= 9.4.0.0 < 9.4.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.5.0.0 < 9.5.9.0
Hpe ≫ Edgeconnect Operating System Version >= 9.6.0.0 < 9.6.4.0
Hpe ≫ Edgeconnect Operating System Version 9.7.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HPE 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
Vendor Advisory