CVE-2026-76703

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
15/09/2026
Last modified:
28/09/2026

Description

A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.4.0 (including) 9.4.11 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.5.0 (including) 9.5.9 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* 9.6.0 (including) 9.6.4 (excluding)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.4.0.0 (including) 9.4.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.5.0.0 (including) 9.5.9.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:* 9.6.0.0 (including) 9.6.4.0 (excluding)
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*