CVE-2026-76689
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.7.0.0 <= 9.7.0.0 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.6.0.0 <= 9.6.3.1 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.5.0.0 <= 9.5.8.1 | affected |
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.4.0.0 <= 9.4.8.2 | affected |
Weaknesses
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.