Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.
| Vendor | Product | Versions |
|---|---|---|
| hewlett packard enterprise (hpe) | edgeconnect sd-wan gateways | 9.7.0, 9.6.0, 9.5.0, 9.4.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | edgeconnect | cert_advisory | 90% |
Loading…