ZeroHour

CVE-2026-76693

moderate

Unauthenticated Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-76693 is a resource-exhaustion flaw (CWE-400) in HPE Networking EdgeConnect SD-WAN Gateways that lets an unauthenticated remote attacker send crafted traffic to certain services on an impacted gateway and crash or degrade them, causing denial of service. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H, base score 7.0 High) additionally credits low confidentiality and integrity impact, so minor information-integrity side effects are possible, though availability is the primary concern. Exploitation requires no credentials or user interaction but involves high attack complexity, meaning it is not trivially weaponizable. Any organization routing traffic through affected EdgeConnect (formerly Silver Peak Unity) gateways is impacted, with branch sites losing SD-WAN connectivity if a gateway is taken offline. There is no known public proof of concept and the CVE is not in the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently indicated.

What to do: Patch impacted EdgeConnect gateways to the fixed firmware version listed in HPE's security bulletin as soon as it is available. In the interim, restrict gateway management and vulnerable service ports to trusted networks via firewall rules or ACLs, and avoid exposing gateway interfaces directly to the internet. Monitor gateway CPU/memory and service health for unexplained exhaustion, and verify which firmware versions in your estate fall in the affected range from the HPE advisory.

Affected
HPE (HPE Aruba Networking) EdgeConnect SD-WAN Gateway
Estimated exposure
moderate≈ low-thousands of internet-exposed gateway appliances; installed base plausibly tens of thousands of appliances across enterprise branch sites (estimate) — EdgeConnect is a leading enterprise SD-WAN platform with thousands of enterprise customers and many branch appliances each, and public scan services historically show low-thousands of exposed EdgeConnect/Unity gateway and management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.

Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.