ZeroHour

CVE-2026-76679

moderate

Unauthenticated Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76679 is a denial-of-service vulnerability in HPE Networking EdgeConnect SD-WAN Gateway appliances that can be triggered by an unauthenticated attacker with access to the network segment adjacent to the gateway (the CVSS vector also scores it as network-reachable with no privileges, no user interaction, and low complexity). Successful exploitation crashes the gateway, and critically, the device does not recover on its own — a manual intervention is required to bring it back up, prolonging the outage. This directly disrupts SD-WAN operations at the affected site, including branch-to-branch and branch-to-data-center connectivity for any organization relying on the gateway. All deployments of HPE Networking (formerly Aruba/Silver Peak) EdgeConnect SD-WAN Gateways described in the advisory are affected; no specific version range was provided in the available data, so defenders should consult the HPE bulletin. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported as of this analysis.

What to do: Apply the patched firmware versions specified in the HPE Security Bulletin for EdgeConnect SD-WAN Gateways as soon as it is available, and prioritize gateways in untrusted or shared network segments. Mitigate by restricting which subnets and VLANs can reach the gateway's data-plane and management interfaces with ACLs and segmentation, since exploitation requires no authentication. Verify you have out-of-band or console access to each site so a crashed gateway can be manually recovered quickly, and monitor appliances for unexpected crashes or non-responsive edge devices.

Affected
HPE (Hewlett Packard Enterprise) Networking EdgeConnect SD-WAN Gateway
Estimated exposure
moderate≈ low tens of thousands of gateway appliances (thousands of enterprise SD-WAN deployments worldwide) — HPE/Aruba EdgeConnect is a major enterprise SD-WAN platform typically deployed as multiple appliances per organization across hundreds to a few thousand enterprise customers, with public internet scans historically showing on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.