CVE-2026-76696
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
15/09/2026
Last modified:
28/09/2026
Description
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* | 9.4.0 (including) | 9.4.11 (excluding) |
| cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* | 9.5.0 (including) | 9.5.9 (excluding) |
| cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* | 9.6.0 (including) | 9.6.4 (excluding) |
| cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* | 9.4.0.0 (including) | 9.4.9.0 (excluding) |
| cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* | 9.5.0.0 (including) | 9.5.9.0 (excluding) |
| cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* | 9.6.0.0 (including) | 9.6.4.0 (excluding) |
| cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page


