ZeroHour

CVE-2026-76692

moderate

Unauthenticated Memory Disclosure and DoS in HPE EdgeConnect SD-WAN Gateways

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76692 is a flaw in HPE Networking EdgeConnect SD-WAN Gateways that lets an unauthenticated attacker on an adjacent network (i.e., able to reach the gateway directly, such as a compromised peer or an on-segment host) read limited uninitialized stack memory and disrupt the affected service. Triggering the flaw causes the gateway service to crash, producing a denial of service, and may leak remnants of uninitialized stack memory to the attacker. The impact is availability loss (system crash) plus low confidentiality impact (limited information disclosure); no code execution or integrity impact is described. Affected products are HPE Networking EdgeConnect SD-WAN Gateway appliances; the advisory does not enumerate specific firmware versions. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not indicated.

What to do: Review the HPE security bulletin for CVE-2026-76692 and upgrade affected EdgeConnect SD-WAN Gateway appliances to the fixed firmware version it specifies. Restrict which hosts and peers can reach gateway control/data interfaces at the network layer so only trusted adjacent systems communicate with the appliance. Monitor gateways for unexpected service crashes or restarts, which would be the primary indicator of exploitation attempts.

Affected
Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Gateway
Estimated exposure
moderate≈10,000+ enterprise SD-WAN deployments (tens of thousands of gateway appliances at branches/data centers), estimate only — HPE/Aruba marketing materials cite on the order of 10,000+ EdgeConnect SD-WAN enterprise customers, each typically operating multiple gateway appliances; the adjacent-network attack vector further limits who can exploit it to hosts that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.

Weakness
CWE-200
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

In the news

No ingested article mentions this CVE yet.