ZeroHour

CVE-2026-73785

niche

Unauthenticated Denial-of-Service Flaw in HPE IceWall Federation Agent and Proxy

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

HPE has disclosed CVE-2026-73785, a denial-of-service vulnerability in the IceWall Federation Agent and Proxy in which the software improperly handles input of an unexpected data type (CWE-241). A remote, unauthenticated attacker can trigger the flaw by sending crafted input to a network-reachable Federation Agent or Proxy service. The issue affects availability only (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), so an attacker can crash or hang the service but gains no access to data. Any organization running HPE IceWall Federation Agent or Proxy — components of HPE's federated single sign-on offering, used primarily by enterprises in Japan — is affected. There is no public proof of concept, no confirmed in-the-wild exploitation, and the flaw is not listed in CISA's KEV catalog.

What to do: Inventory your environment for IceWall Federation Agent and Proxy deployments and consult the HPE security bulletin for patched releases, since affected and fixed version details were not included in the disclosure data. Until you can patch, restrict network access to these services (e.g., allow only trusted federation partners) and monitor service availability; there is no known exploitation at this time.

Affected
HPE IceWall Federation Agent
HPE IceWall Proxy
Estimated exposure
nichelikely only thousands of enterprise deployments at most (no public install counts) — HPE does not publish IceWall install-base figures, the product is a legacy federated-SSO component sold mainly to Japanese enterprises and is rarely observed in public internet-exposure scans, so this is a rough order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

Weakness
CWE-241
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.