Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN898
_____________________________________________________________________

DATE                : 16/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running HPE Networking EdgeConnect
                 SD-WAN Gateways versions prior to 9.7.1.0, 9.6.4.0,
                                      9.5.9.0, 9.4.9.0,
                 HPE Networking SD-WAN Orchestrator versions prior 
                             to 9.7.1, 9.6.4, 9.5.9, 9.4.11.
  
=====================================================================
https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05135.txt
_____________________________________________________________________

HPE Networking Product Security Advisory
==============================================
Advisory ID: HPESBNW05135 
CVE: Please refer to the References section at the end of this
     advisory for the complete list of CVEs.
Publication Date: 2026-Sep-15
Status: FINAL
Last Updated: 2026-Sep-15
Severity: Critical 
Revision: 1


Title
=====
Multiple Vulnerabilities in HPE Networking EdgeConnect
SD-WAN Gateways and SD-WAN Orchestrator.


Summary
========
HPE Networking has released patches for the HPE Networking 
EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator that address 
multiple security vulnerabilities.


Affected Products
=================
These vulnerabilities affect the following HPE Networking 
EdgeConnect SD-WAN software versions unless specifically 
noted otherwise in the details section:

HPE Networking EdgeConnect SD-WAN Gateways
  - ECOS 9.7.x.x: 9.7.0.0 and below
  - ECOS 9.6.x.x: 9.6.3.1 and below
  - ECOS 9.5.x.x: 9.5.8.1 and below
  - ECOS 9.4.x.x: 9.4.8.2 and below

HPE Networking EdgeConnect SD-WAN Orchestrator:
  - Orchestrator 9.7.x: 9.7.0 and below
  - Orchestrator 9.6.x: 9.6.3 and below
  - Orchestrator 9.5.x: 9.5.8 and below
  - Orchestrator 9.4.x: 9.4.10 and below


Unaffected Products
===================
Any other HPE Networking products and software versions not
specifically listed above are not affected by these 
Vulnerabilities.


Workaround
==========
To minimize the likelihood of an attacker exploiting these
vulnerabilities, HPE Networking recommends that the
CLI and web-based management interfaces be restricted to a
dedicated layer 2 segment/VLAN and/or controlled by firewall
policies at layer 3 and above along with accounting controls
for tracking and logging user activities and resource usage.


Exploitation and Public Discussion
==================================
These vulnerabilities were generally discovered by internal
security research at HPE Networking. HPE Networking is not 
aware of any public discussion or exploit code that targets 
the listed vulnerabilities as of the release date of this 
advisory. Customers are strongly urged to patch their instances 
due to the complexity, breadth, and impact of these 
vulnerabilities.

Please note that due to the size of the Details and References 
sections, these sections have been moved to the end of the 
document to improve readability.


Resolution
==========
To address the vulnerabilities described in the Details 
Section, HPE Networking recommends upgrading the HPE Networking 
EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator to the 
following software versions (as applicable):

HPE Networking EdgeConnect SD-WAN Gateways
  - ECOS 9.7.1.0 and above 
  - ECOS 9.6.4.0 and above 
  - ECOS 9.5.9.0 and above 
  - ECOS 9.4.9.0 and above 
 

HPE Networking SD-WAN Orchestrator
  - Orchestrator 9.7.1 and above
  - Orchestrator 9.6.4 and above
  - Orchestrator 9.5.9 and above
  - Orchestrator 9.4.11 and above

IMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator 
software version must be greater than or equal to the ECOS 
software version running on any HPE Networking EdgeConnect SD-WAN 
Gateways.

Software versions with resolution/fixes for the vulnerabilities 
covered above can be downloaded from the HPE Networking
Support Portal at: https://networkingsupport.hpe.com

NOTE: Product software versions that have reached End of
Maintenance (EoM) are presumed to be affected by the
vulnerabilities unless explicitly stated otherwise and are
not covered by this security advisory. For deployments
running software versions that are past End of Support
(EoS), HPE Networking has not assessed exposure to the
vulnerabilities referenced in this advisory. As a result,
such installations should be considered potentially impacted
by the listed CVE. Customers are strongly encouraged to
upgrade to a supported software release to ensure proper
evaluation and remediation.

For more information about the HPE Networking EdgeConnect 
SD-WAN End-of-Support policy, please visit: 
https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf 


Revision History
================
Revision 1 / 2026-Sep-15 / Initial release


HPE Networking SIRT Security Procedures
=============================================
Complete information on reporting security vulnerabilities
in HPE Networking products and obtaining assistance
with security incidents is available at:
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us
 
For reporting *NEW* HPE Networking security issues,
email can be sent to networking-sirt(at)hpe.com. For sensitive
information we encourage the use of PGP encryption. Our
public keys can be found at:
https://www.hpe.com/info/psrt-pgp-key

(c) Copyright 2026 by Hewlett Packard Enterprise Development
LP. This advisory may be redistributed freely after the
release date given at the top of the text, provided that the
redistributed copies are complete and unmodified, including
all data and version information.


Details
=======
Authorization Bypass Leading to Privilege Escalation in EdgeConnect 
SD-WAN Orchestrator
(CVE-2026-76669, CVE-2026-76670)
  -----------------------------------------------------------------
  Privilege escalation vulnerabilities exist in the API of HPE 
  Networking EdgeConnect SD-WAN Orchestrator. Successful 
  exploitation could allow a remote low-privileged authenticated 
  user to escalate their privileges to those of an administrative 
  user, leading to complete system compromise.
 
  Internal References: VULN-661, VULN-664, VULN-669, 
                       VULN-670
  Severity: Critical
  CVSS v3.1 Base Score: 9.9
  CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
 
  Acknowledgements: Internal security research (HPE Networking); 
                    Christopher Alejandro (Moroco).
 

Authenticated Sensitive Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Orchestrator
(CVE-2026-76672)
  -----------------------------------------------------------------
    A vulnerability exists in the SD-WAN Orchestrator that may lead 
    to the exposure of sensitive configuration information. An 
    authenticated remote attacker with read-only privileges could 
    exploit this vulnerability by sending a specially crafted request 
    to the cache synchronization endpoint. Successful exploitation 
    could result in the disclosure of sensitive third-party API tokens 
    and credentials, potentially enabling lateral movement to external 
    security platforms.
 
    Internal Reference: VULN-677
    Severity: Critical
    CVSS v3.1 Base Score: 9.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
 
    Acknowledgements: Internal security research (HPE Networking).

    
Authentication Bypass Vulnerabilities in API of EdgeConnect 
SD-WAN Orchestrator
(CVE-2026-76673)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the API of EdgeConnect 
    SD-WAN Orchestrator that could potentially allow an 
    unauthenticated remote actor to circumvent existing authentication 
    controls. Successful exploitation could allow an attacker to 
    gain administrative privileges leading to complete compromise 
    of the EdgeConnect SD-WAN Orchestrator host.
 
    Internal References: VULN-659, VULN-660
    Severity: Critical
    CVSS v3.1 Base Score: 9.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76674)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying operating 
    system of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated remote attacker to execute arbitrary 
    code. Successful exploitation could allow an attacker to execute 
    arbitrary commands on the underlying operating system leading to 
    complete system compromise.
 
    Internal References: VULN-680, VULN-681
    Severity: Critical
    CVSS v3.1 Base Score: 9.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).

    
Authenticated Command Injection Vulnerability Leads to Privilege 
Escalation in EdgeConnect SD-WAN Gateways
(CVE-2026-76675)
  -----------------------------------------------------------------
    A command injection vulnerability exists in the command line 
    interface of EdgeConnect SD-WAN Gateways. Successful 
    exploitation could allow an authenticated remote attacker with 
    high privileges to execute arbitrary commands on the underlying 
    operating system leading to complete system compromise.
 
    Internal References: VULN-693
    Severity: Critical
    CVSS v3.1 Base Score: 9.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
 
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in EdgeConnect SD-WAN Gateways
(CVE-2026-76676)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying 
    operating system of EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated adjacent attacker to execute arbitrary 
    code if certain preconditions outside of the attacker's 
    control are met. Successful exploitation could allow an 
    attacker to execute arbitrary code as a privileged user on 
    the underlying operating system leading to complete system 
    compromise.
 
    Internal References:  VULN-686, VULN-698
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements:
    Internal security research (HPE Networking).
 
    
Authorization Bypass Leading to Privilege Escalation in HPE 
Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76677)
    -----------------------------------------------------------------
    A privilege escalation vulnerability exists in the API of 
    EdgeConnect SD-WAN Gateways. Successful exploitation could allow 
    a remote low-privileged authenticated user to achieve 
    administrative privilege on the web-management interface 
    leading to complete system compromise.
 
    Internal References: VULN-671
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).
 
    
Authenticated Command Injection Vulnerability leads to Remote 
Code Execution in EdgeConnect SD-WAN Gateways
(CVE-2026-76678)
    -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking EdgeConnect 
    SD-WAN Gateways could allow a low-privilege authenticated remote 
    attacker to escalate privileges. Successful exploitation of this 
    vulnerability may enable the attacker to execute arbitrary system 
    commands with root privileges on the underlying operating system.
 
    Internal References: VULN-707, VULN-708
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).


Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76679)
  -----------------------------------------------------------------
    Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to conduct 
    denial-of-service attacks. Successful exploitation could allow 
    an attacker to crash the system, preventing it from rebooting 
    without manual intervention and disrupting network operations.
 
    Internal References: VULN-650, VULN-651, VULN-655, VULN-682, 
                         VULN-687, VULN-688, VULN-689, VULN-691, 
                         VULN-695, VULN-706
    Severity: High
    CVSS v3.1 Base Score: 8.6
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).


Authenticated Server-Side Request Forgery Vulnerabilities Leading 
to Information Disclosure in EdgeConnect SD-WAN Orchestrator
(CVE-2026-76680)
  -----------------------------------------------------------------
    Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator 
    could allow a remote attacker authenticated with low privileges 
    to conduct server-side request forgery (SSRF) attacks. A 
    successful exploit allows an attacker to enumerate information 
    about the internal structure of the EdgeConnect SD-WAN 
    Orchestrator host leading to potential disclosure of sensitive 
    information beyond what is authorized by the user's existing 
    privilege level.
 
    Internal References: VULN-672, VULN-675
    Severity: High
    CVSS v3.1 Base Score: 8.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
 
    Acknowledgements: Internal security research (HPE Networking).

 
Authenticated Information Disclosure Vulnerability in HPE Networking 
EdgeConnect SD-WAN Orchestrator API
(CVE-2026-76681)
  -----------------------------------------------------------------
    A vulnerability in the API of EdgeConnect SD-WAN Orchestrator 
    could allow an authenticated remote attacker with low privileges 
    to access sensitive information beyond what is authorized by 
    the user's existing privilege level. Successful exploitation 
    could allow an attacker to retrieve information which could 
    be used to potentially gain further access to network services 
    supported by EdgeConnect SD-WAN Orchestrator.
 
    Internal References: VULN-673, VULN-674, VULN-676
    Severity: High
    CVSS v3.1 Base Score: 8.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76682)
  -----------------------------------------------------------------
    A vulnerability in the network security monitoring component of
    intrusion detection systems could allow an unauthenticated 
    remote attacker to exploit a limited buffer overflow. 
    Successful exploitation could allow an attacker to cause a 
    denial-of-service or potentially execute arbitrary code on the 
    system.
 
    Internal References: VULN-643, VULN-652, VULN-697, 
                         VULN-705
    Severity: High
    CVSS v3.1 Base Score: 8.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76683)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways that could allow an 
    unauthenticated remote attacker to run arbitrary commands on 
    the underlying host if certain preconditions outside of the 
    attacker's control are met. Successful exploitation could allow 
    an attacker to execute arbitrary commands on the underlying 
    operating system leading to complete system compromise.
 
    Internal References: VULN-641, VULN-644
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authentication Bypass Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Orchestrator API
(CVE-2026-76684)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the API of HPE 
    Networking EdgeConnect SD-WAN Orchestrator that could 
    potentially allow an unauthenticated remote actor to 
    circumvent existing authentication controls. Successful
    exploitation could allow an attacker to gain administrative 
    privileges leading to complete compromise of the EdgeConnect 
    SD-WAN Orchestrator host.
 
    Internal References: VULN-662, VULN-663
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
    

Unauthenticated Buffer Overflow Vulnerability leads to Remote 
Code Execution or Denial-of-Service in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76685)
  -----------------------------------------------------------------
    A vulnerability exists in the proxy packet processing logic 
    of the affected component where it improperly processes 
    malformed or truncated input. An unauthenticated remote 
    attacker could exploit this vulnerability by providing specially 
    crafted input that triggers an integer overflow. Successful 
    exploitation could result in a buffer overflow, potentially 
    leading to remote code execution or denial-of-service.
 
    Internal References: VULN-709
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).
 

Unauthenticated Denial-of-Service (DoS) Vulnerability leads to 
Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76686)
  -----------------------------------------------------------------
    A vulnerability exists in the underlying operating system of HPE 
    Networking EdgeConnect SD-WAN Gateways. Successful exploitation 
    could allow an unauthenticated remote attacker to conduct a 
    denial-of-service attack on the affected service.
 
    Internal References: VULN-634, VULN-635, VULN-636, 
                         VULN-684, VULN-685, VULN-696
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Authenticated Arbitrary File Write Leading to Remote Code Execution 
in EdgeConnect SD-WAN Orchestrator
(CVE-2026-76687)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Orchestrator could allow a low-privilege
    authenticated remote attacker to escalate privileges. Successful
    exploitation of this vulnerability may enable the attacker to 
    execute arbitrary system commands with root privileges on the 
    underlying operating system.
 
    Internal References: VULN-668
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authentication Bypass Vulnerabilities in the Web-Based Management 
Interface of EdgeConnect SD-WAN Orchestrator
(CVE-2026-76688)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the web-based management
    interface of EdgeConnect SD-WAN Orchestrator that could potentially
    allow an unauthenticated remote actor to circumvent existing
    authentication controls. Successful exploitation could allow an
    attacker to gain administrative privileges leading to complete
    compromise of the EdgeConnect SD-WAN Orchestrator host.
 
    Internal References: VULN-665, VULN-666
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Buffer Overflow Vulnerability leads to Remote 
Code Execution or Denial-of-Service in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76689)
  -----------------------------------------------------------------
    A vulnerability exists in the configuration processing logic of 
    the affected component where malformed input is improperly 
    processed. An authenticated remote attacker with administrative 
    privileges could exploit this vulnerability by providing specially 
    crafted configuration data. Successful exploitation could result 
    in a stack-based buffer overflow, potentially leading to remote 
    code execution with root privileges or a denial of service due 
    to a system crash.

    Internal References: VULN-637
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Remote Code Execution Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76690)
  -----------------------------------------------------------------
    A vulnerability exists in a component of the HPE Networking 
    EdgeConnect SD-WAN Gateways that may allow for arbitrary 
    command execution. An authenticated remote attacker could 
    exploit this vulnerability by providing a specially crafted 
    input to the affected component. Successful exploitation 
    could result in remote code execution as root.
  
    Internal References: VULN-642, VULN-701
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code 
Execution in HPE Networking EdgeConnect SD-WAN Gateway API Endpoint
(CVE-2026-76691)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation 
    could allow an authenticated remote attacker to execute arbitrary 
    commands as a privileged user on the underlying operating system.
 
    Internal References: VULN-692, VULN-699, VULN-703
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
    

Unauthenticated Adjacent Information Disclosure and Denial-of-Service 
Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76692)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to obtain 
    limited information from memory and disrupt the normal 
    operation of the affected service. Successful exploitation 
    could result in a denial of service (system crash) or the 
    disclosure of uninitialized stack memory.
 
    Internal References: VULN-710, VULN-712, VULN-694
    Severity: High
    CVSS v3.1 Base Score: 7.1
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76693)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated remote attacker to cause a 
    denial-of-Service against certain services running on impacted 
    Gateways. 
 
    Internal References: VULN-638, VULN-653
    Severity: High
    CVSS v3.1 Base Score: 7.0
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Authenticated Privilege Escalation Vulnerability in the Command 
Line Interface of HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76694)
  -----------------------------------------------------------------
    A privilege escalation vulnerability exists in the command line
=======
HPE Networking Product Security Advisory
==============================================
Advisory ID: HPESBNW05135 
CVE: Please refer to the References section at the end of this
     advisory for the complete list of CVEs.
Publication Date: 2026-Sep-15
Status: FINAL
Last Updated: 2026-Sep-15
Severity: Critical 
Revision: 1


Title
=====
Multiple Vulnerabilities in HPE Networking EdgeConnect
SD-WAN Gateways and SD-WAN Orchestrator.


Summary
========
HPE Networking has released patches for the HPE Networking 
EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator that address 
multiple security vulnerabilities.


Affected Products
=================
These vulnerabilities affect the following HPE Networking 
EdgeConnect SD-WAN software versions unless specifically 
noted otherwise in the details section:

HPE Networking EdgeConnect SD-WAN Gateways
  - ECOS 9.7.x.x: 9.7.0.0 and below
  - ECOS 9.6.x.x: 9.6.3.1 and below
  - ECOS 9.5.x.x: 9.5.8.1 and below
  - ECOS 9.4.x.x: 9.4.8.2 and below

HPE Networking EdgeConnect SD-WAN Orchestrator:
  - Orchestrator 9.7.x: 9.7.0 and below
  - Orchestrator 9.6.x: 9.6.3 and below
  - Orchestrator 9.5.x: 9.5.8 and below
  - Orchestrator 9.4.x: 9.4.10 and below


Unaffected Products
===================
Any other HPE Networking products and software versions not
specifically listed above are not affected by these 
Vulnerabilities.


Workaround
==========
To minimize the likelihood of an attacker exploiting these
vulnerabilities, HPE Networking recommends that the
CLI and web-based management interfaces be restricted to a
dedicated layer 2 segment/VLAN and/or controlled by firewall
policies at layer 3 and above along with accounting controls
for tracking and logging user activities and resource usage.


Exploitation and Public Discussion
==================================
These vulnerabilities were generally discovered by internal
security research at HPE Networking. HPE Networking is not 
aware of any public discussion or exploit code that targets 
the listed vulnerabilities as of the release date of this 
advisory. Customers are strongly urged to patch their instances 
due to the complexity, breadth, and impact of these 
vulnerabilities.

Please note that due to the size of the Details and References 
sections, these sections have been moved to the end of the 
document to improve readability.


Resolution
==========
To address the vulnerabilities described in the Details 
Section, HPE Networking recommends upgrading the HPE Networking 
EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator to the 
following software versions (as applicable):

HPE Networking EdgeConnect SD-WAN Gateways
  - ECOS 9.7.1.0 and above 
  - ECOS 9.6.4.0 and above 
  - ECOS 9.5.9.0 and above 
  - ECOS 9.4.9.0 and above 
 

HPE Networking SD-WAN Orchestrator
  - Orchestrator 9.7.1 and above
  - Orchestrator 9.6.4 and above
  - Orchestrator 9.5.9 and above
  - Orchestrator 9.4.11 and above

IMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator 
software version must be greater than or equal to the ECOS 
software version running on any HPE Networking EdgeConnect SD-WAN 
Gateways.

Software versions with resolution/fixes for the vulnerabilities 
covered above can be downloaded from the HPE Networking
Support Portal at: https://networkingsupport.hpe.com

NOTE: Product software versions that have reached End of
Maintenance (EoM) are presumed to be affected by the
vulnerabilities unless explicitly stated otherwise and are
not covered by this security advisory. For deployments
running software versions that are past End of Support
(EoS), HPE Networking has not assessed exposure to the
vulnerabilities referenced in this advisory. As a result,
such installations should be considered potentially impacted
by the listed CVE. Customers are strongly encouraged to
upgrade to a supported software release to ensure proper
evaluation and remediation.

For more information about the HPE Networking EdgeConnect 
SD-WAN End-of-Support policy, please visit: 
https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf 


Revision History
================
Revision 1 / 2026-Sep-15 / Initial release


HPE Networking SIRT Security Procedures
=============================================
Complete information on reporting security vulnerabilities
in HPE Networking products and obtaining assistance
with security incidents is available at:
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us
 
For reporting *NEW* HPE Networking security issues,
email can be sent to networking-sirt(at)hpe.com. For sensitive
information we encourage the use of PGP encryption. Our
public keys can be found at:
https://www.hpe.com/info/psrt-pgp-key

(c) Copyright 2026 by Hewlett Packard Enterprise Development
LP. This advisory may be redistributed freely after the
release date given at the top of the text, provided that the
redistributed copies are complete and unmodified, including
all data and version information.


Details
=======
Authorization Bypass Leading to Privilege Escalation in EdgeConnect 
SD-WAN Orchestrator
(CVE-2026-76669, CVE-2026-76670)
  -----------------------------------------------------------------
  Privilege escalation vulnerabilities exist in the API of HPE 
  Networking EdgeConnect SD-WAN Orchestrator. Successful 
  exploitation could allow a remote low-privileged authenticated 
  user to escalate their privileges to those of an administrative 
  user, leading to complete system compromise.
 
  Internal References: VULN-661, VULN-664, VULN-669, 
                       VULN-670
  Severity: Critical
  CVSS v3.1 Base Score: 9.9
  CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
 
  Acknowledgements: Internal security research (HPE Networking); 
                    Christopher Alejandro (Moroco).
 

Authenticated Sensitive Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Orchestrator
(CVE-2026-76672)
  -----------------------------------------------------------------
    A vulnerability exists in the SD-WAN Orchestrator that may lead 
    to the exposure of sensitive configuration information. An 
    authenticated remote attacker with read-only privileges could 
    exploit this vulnerability by sending a specially crafted request 
    to the cache synchronization endpoint. Successful exploitation 
    could result in the disclosure of sensitive third-party API tokens 
    and credentials, potentially enabling lateral movement to external 
    security platforms.
 
    Internal Reference: VULN-677
    Severity: Critical
    CVSS v3.1 Base Score: 9.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
 
    Acknowledgements: Internal security research (HPE Networking).

    
Authentication Bypass Vulnerabilities in API of EdgeConnect 
SD-WAN Orchestrator
(CVE-2026-76673)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the API of EdgeConnect 
    SD-WAN Orchestrator that could potentially allow an 
    unauthenticated remote actor to circumvent existing authentication 
    controls. Successful exploitation could allow an attacker to 
    gain administrative privileges leading to complete compromise 
    of the EdgeConnect SD-WAN Orchestrator host.
 
    Internal References: VULN-659, VULN-660
    Severity: Critical
    CVSS v3.1 Base Score: 9.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76674)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying operating 
    system of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated remote attacker to execute arbitrary 
    code. Successful exploitation could allow an attacker to execute 
    arbitrary commands on the underlying operating system leading to 
    complete system compromise.
 
    Internal References: VULN-680, VULN-681
    Severity: Critical
    CVSS v3.1 Base Score: 9.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).

    
Authenticated Command Injection Vulnerability Leads to Privilege 
Escalation in EdgeConnect SD-WAN Gateways
(CVE-2026-76675)
  -----------------------------------------------------------------
    A command injection vulnerability exists in the command line 
    interface of EdgeConnect SD-WAN Gateways. Successful 
    exploitation could allow an authenticated remote attacker with 
    high privileges to execute arbitrary commands on the underlying 
    operating system leading to complete system compromise.
 
    Internal References: VULN-693
    Severity: Critical
    CVSS v3.1 Base Score: 9.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
 
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in EdgeConnect SD-WAN Gateways
(CVE-2026-76676)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying 
    operating system of EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated adjacent attacker to execute arbitrary 
    code if certain preconditions outside of the attacker's 
    control are met. Successful exploitation could allow an 
    attacker to execute arbitrary code as a privileged user on 
    the underlying operating system leading to complete system 
    compromise.
 
    Internal References:  VULN-686, VULN-698
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements:
    Internal security research (HPE Networking).
 
    
Authorization Bypass Leading to Privilege Escalation in HPE 
Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76677)
    -----------------------------------------------------------------
    A privilege escalation vulnerability exists in the API of 
    EdgeConnect SD-WAN Gateways. Successful exploitation could allow 
    a remote low-privileged authenticated user to achieve 
    administrative privilege on the web-management interface 
    leading to complete system compromise.
 
    Internal References: VULN-671
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).
 
    
Authenticated Command Injection Vulnerability leads to Remote 
Code Execution in EdgeConnect SD-WAN Gateways
(CVE-2026-76678)
    -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking EdgeConnect 
    SD-WAN Gateways could allow a low-privilege authenticated remote 
    attacker to escalate privileges. Successful exploitation of this 
    vulnerability may enable the attacker to execute arbitrary system 
    commands with root privileges on the underlying operating system.
 
    Internal References: VULN-707, VULN-708
    Severity: High
    CVSS v3.1 Base Score: 8.8
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).


Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76679)
  -----------------------------------------------------------------
    Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to conduct 
    denial-of-service attacks. Successful exploitation could allow 
    an attacker to crash the system, preventing it from rebooting 
    without manual intervention and disrupting network operations.
 
    Internal References: VULN-650, VULN-651, VULN-655, VULN-682, 
                         VULN-687, VULN-688, VULN-689, VULN-691, 
                         VULN-695, VULN-706
    Severity: High
    CVSS v3.1 Base Score: 8.6
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).


Authenticated Server-Side Request Forgery Vulnerabilities Leading 
to Information Disclosure in EdgeConnect SD-WAN Orchestrator
(CVE-2026-76680)
  -----------------------------------------------------------------
    Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator 
    could allow a remote attacker authenticated with low privileges 
    to conduct server-side request forgery (SSRF) attacks. A 
    successful exploit allows an attacker to enumerate information 
    about the internal structure of the EdgeConnect SD-WAN 
    Orchestrator host leading to potential disclosure of sensitive 
    information beyond what is authorized by the user's existing 
    privilege level.
 
    Internal References: VULN-672, VULN-675
    Severity: High
    CVSS v3.1 Base Score: 8.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
 
    Acknowledgements: Internal security research (HPE Networking).

 
Authenticated Information Disclosure Vulnerability in HPE Networking 
EdgeConnect SD-WAN Orchestrator API
(CVE-2026-76681)
  -----------------------------------------------------------------
    A vulnerability in the API of EdgeConnect SD-WAN Orchestrator 
    could allow an authenticated remote attacker with low privileges 
    to access sensitive information beyond what is authorized by 
    the user's existing privilege level. Successful exploitation 
    could allow an attacker to retrieve information which could 
    be used to potentially gain further access to network services 
    supported by EdgeConnect SD-WAN Orchestrator.
 
    Internal References: VULN-673, VULN-674, VULN-676
    Severity: High
    CVSS v3.1 Base Score: 8.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76682)
  -----------------------------------------------------------------
    A vulnerability in the network security monitoring component of
    intrusion detection systems could allow an unauthenticated 
    remote attacker to exploit a limited buffer overflow. 
    Successful exploitation could allow an attacker to cause a 
    denial-of-service or potentially execute arbitrary code on the 
    system.
 
    Internal References: VULN-643, VULN-652, VULN-697, 
                         VULN-705
    Severity: High
    CVSS v3.1 Base Score: 8.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote 
Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76683)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways that could allow an 
    unauthenticated remote attacker to run arbitrary commands on 
    the underlying host if certain preconditions outside of the 
    attacker's control are met. Successful exploitation could allow 
    an attacker to execute arbitrary commands on the underlying 
    operating system leading to complete system compromise.
 
    Internal References: VULN-641, VULN-644
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authentication Bypass Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Orchestrator API
(CVE-2026-76684)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the API of HPE 
    Networking EdgeConnect SD-WAN Orchestrator that could 
    potentially allow an unauthenticated remote actor to 
    circumvent existing authentication controls. Successful
    exploitation could allow an attacker to gain administrative 
    privileges leading to complete compromise of the EdgeConnect 
    SD-WAN Orchestrator host.
 
    Internal References: VULN-662, VULN-663
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
    

Unauthenticated Buffer Overflow Vulnerability leads to Remote 
Code Execution or Denial-of-Service in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76685)
  -----------------------------------------------------------------
    A vulnerability exists in the proxy packet processing logic 
    of the affected component where it improperly processes 
    malformed or truncated input. An unauthenticated remote 
    attacker could exploit this vulnerability by providing specially 
    crafted input that triggers an integer overflow. Successful 
    exploitation could result in a buffer overflow, potentially 
    leading to remote code execution or denial-of-service.
 
    Internal References: VULN-709
    Severity: High
    CVSS v3.1 Base Score: 8.1
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: 
    Internal security research (HPE Networking).
 

Unauthenticated Denial-of-Service (DoS) Vulnerability leads to 
Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76686)
  -----------------------------------------------------------------
    A vulnerability exists in the underlying operating system of HPE 
    Networking EdgeConnect SD-WAN Gateways. Successful exploitation 
    could allow an unauthenticated remote attacker to conduct a 
    denial-of-service attack on the affected service.
 
    Internal References: VULN-634, VULN-635, VULN-636, 
                         VULN-684, VULN-685, VULN-696
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Authenticated Arbitrary File Write Leading to Remote Code Execution 
in EdgeConnect SD-WAN Orchestrator
(CVE-2026-76687)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Orchestrator could allow a low-privilege
    authenticated remote attacker to escalate privileges. Successful
    exploitation of this vulnerability may enable the attacker to 
    execute arbitrary system commands with root privileges on the 
    underlying operating system.
 
    Internal References: VULN-668
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authentication Bypass Vulnerabilities in the Web-Based Management 
Interface of EdgeConnect SD-WAN Orchestrator
(CVE-2026-76688)
  -----------------------------------------------------------------
    Vulnerabilities have been identified in the web-based management
    interface of EdgeConnect SD-WAN Orchestrator that could potentially
    allow an unauthenticated remote actor to circumvent existing
    authentication controls. Successful exploitation could allow an
    attacker to gain administrative privileges leading to complete
    compromise of the EdgeConnect SD-WAN Orchestrator host.
 
    Internal References: VULN-665, VULN-666
    Severity: High
    CVSS v3.1 Base Score: 7.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Buffer Overflow Vulnerability leads to Remote 
Code Execution or Denial-of-Service in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76689)
  -----------------------------------------------------------------
    A vulnerability exists in the configuration processing logic of 
    the affected component where malformed input is improperly 
    processed. An authenticated remote attacker with administrative 
    privileges could exploit this vulnerability by providing specially 
    crafted configuration data. Successful exploitation could result 
    in a stack-based buffer overflow, potentially leading to remote 
    code execution with root privileges or a denial of service due 
    to a system crash.

    Internal References: VULN-637
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Remote Code Execution Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76690)
  -----------------------------------------------------------------
    A vulnerability exists in a component of the HPE Networking 
    EdgeConnect SD-WAN Gateways that may allow for arbitrary 
    command execution. An authenticated remote attacker could 
    exploit this vulnerability by providing a specially crafted 
    input to the affected component. Successful exploitation 
    could result in remote code execution as root.
  
    Internal References: VULN-642, VULN-701
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code 
Execution in HPE Networking EdgeConnect SD-WAN Gateway API Endpoint
(CVE-2026-76691)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation 
    could allow an authenticated remote attacker to execute arbitrary 
    commands as a privileged user on the underlying operating system.
 
    Internal References: VULN-692, VULN-699, VULN-703
    Severity: High
    CVSS v3.1 Base Score: 7.2
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
    

Unauthenticated Adjacent Information Disclosure and Denial-of-Service 
Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76692)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to obtain 
    limited information from memory and disrupt the normal 
    operation of the affected service. Successful exploitation 
    could result in a denial of service (system crash) or the 
    disclosure of uninitialized stack memory.
 
    Internal References: VULN-710, VULN-712, VULN-694
    Severity: High
    CVSS v3.1 Base Score: 7.1
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76693)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated remote attacker to cause a 
    denial-of-Service against certain services running on impacted 
    Gateways. 
 
    Internal References: VULN-638, VULN-653
    Severity: High
    CVSS v3.1 Base Score: 7.0
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Authenticated Privilege Escalation Vulnerability in the Command 
Line Interface of HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76694)
  -----------------------------------------------------------------
    A privilege escalation vulnerability exists in the command line
>>>>>>> ed8ee2d78ca126b30a110da30493ff3492898cfd
    interface of HPE Networking EdgeConnect SD-WAN Gateways. 
    Successful exploitation could allow an authenticated remote 
    attacker with high privileges to escalate privileges beyond 
    their authorized level, and execute arbitrary code on a 
<<<<<<< HEAD
    vulnerable system.
 
    Internal References: VULN-646
    Severity: Medium
    CVSS v3.1 Base Score: 6.6
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76695)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying operating 
    system of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated remote attacker to send specially 
    crafted packets to the affected service. Successful exploitation 
    could allow an attacker to affect the integrity and availability 
    of the affected service.
 
    Internal References: VULN-657, VULN-658, VULN-690
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service (DoS) Vulnerability leads to 
Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76696)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could 
    allow an unauthenticated adjacent attacker to conduct a denial 
    of service attack. Successful exploitation could allow an 
    attacker to crash the system, preventing it from rebooting 
    without manual intervention and disrupting network operations.
 
    Internal References: VULN-679
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Information Disclosure in HPE Networking EdgeConnect 
Enterprise Web-Based Management Interface
(CVE-2026-76697)
  -----------------------------------------------------------------
    A vulnerability in the web-based management interface of HPE 
    Networking EdgeConnect SD-WAN Gateways could allow a remote attacker 
    Authenticated with low privileges to access sensitive information. 
    A successful exploit allows an attacker to retrieve information 
    which could be used to potentially gain further access to network 
    services supported by HPE Networking EdgeConnect SD-WAN Gateways.
 
    Internal References: VULN-700
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).


Authenticated Command Injection Vulnerability leads to 
Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76698)
  -----------------------------------------------------------------
    A command injection vulnerability exists in the web-based management
    interface of HPE Networking EdgeConnect SD-WAN Gateways. An 
    authenticated remote attacker with limited access privileges 
    could exploit this vulnerability through specially crafted input. 
    Successful exploitation, under certain conditions, could result 
    in the execution of arbitrary commands with elevated privileges 
    or a denial-of-service condition on the affected appliance.
 
    Internal Reference: VULN-702
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking)
 

Unauthenticated Buffer Overflow Vulnerability leads to 
Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76699)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in a system service within 
    the underlying operating system of HPE Networking EdgeConnect 
    SD-WAN Gateways that could allow an unauthenticated adjacent 
    attacker to cause a denial-of-service. Successful exploitation 
    could allow an attacker to crash the impacted service and 
    temporarily disrupting network operations.
 
    Internal References: VULN-713
    Severity: Medium
    CVSS v3.1 Base Score: 6.4
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76700)
  -----------------------------------------------------------------
=======
    vulnerable system.
 
    Internal References: VULN-646
    Severity: Medium
    CVSS v3.1 Base Score: 6.6
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

 
Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76695)
  -----------------------------------------------------------------
    Buffer overflow vulnerabilities exist in the underlying operating 
    system of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an unauthenticated remote attacker to send specially 
    crafted packets to the affected service. Successful exploitation 
    could allow an attacker to affect the integrity and availability 
    of the affected service.
 
    Internal References: VULN-657, VULN-658, VULN-690
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service (DoS) Vulnerability leads to 
Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76696)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could 
    allow an unauthenticated adjacent attacker to conduct a denial 
    of service attack. Successful exploitation could allow an 
    attacker to crash the system, preventing it from rebooting 
    without manual intervention and disrupting network operations.
 
    Internal References: VULN-679
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Information Disclosure in HPE Networking EdgeConnect 
Enterprise Web-Based Management Interface
(CVE-2026-76697)
  -----------------------------------------------------------------
    A vulnerability in the web-based management interface of HPE 
    Networking EdgeConnect SD-WAN Gateways could allow a remote attacker 
    Authenticated with low privileges to access sensitive information. 
    A successful exploit allows an attacker to retrieve information 
    which could be used to potentially gain further access to network 
    services supported by HPE Networking EdgeConnect SD-WAN Gateways.
 
    Internal References: VULN-700
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).


Authenticated Command Injection Vulnerability leads to 
Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76698)
  -----------------------------------------------------------------
    A command injection vulnerability exists in the web-based management
    interface of HPE Networking EdgeConnect SD-WAN Gateways. An 
    authenticated remote attacker with limited access privileges 
    could exploit this vulnerability through specially crafted input. 
    Successful exploitation, under certain conditions, could result 
    in the execution of arbitrary commands with elevated privileges 
    or a denial-of-service condition on the affected appliance.
 
    Internal Reference: VULN-702
    Severity: Medium
    CVSS v3.1 Base Score: 6.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking)
 

Unauthenticated Buffer Overflow Vulnerability leads to 
Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
(CVE-2026-76699)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in a system service within 
    the underlying operating system of HPE Networking EdgeConnect 
    SD-WAN Gateways that could allow an unauthenticated adjacent 
    attacker to cause a denial-of-service. Successful exploitation 
    could allow an attacker to crash the impacted service and 
    temporarily disrupting network operations.
 
    Internal References: VULN-713
    Severity: Medium
    CVSS v3.1 Base Score: 6.4
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76700)
  -----------------------------------------------------------------
>>>>>>> ed8ee2d78ca126b30a110da30493ff3492898cfd
    Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated remote attacker to cause a 
    denial-of-service. Successful exploitation could allow an 
    attacker to interrupt the normal operation of the affected 
<<<<<<< HEAD
    service.
 
    Internal References: VULN-640, VULN-654, VULN-656, VULN-648
    Severity: Medium
    CVSS v3.1 Base Score: 5.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Unauthenticated Sensitive Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76701)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Gateways could allow an unauthenticated 
    remote attacker to access sensitive information. Successful 
    exploitation could allow an attacker to retrieve information 
    which could be used to potentially gain further access to 
    network services supported by HPE Networking EdgeConnect 
    SD-WAN Gateways.
 
    Internal References: VULN-645
    Severity: Medium
    CVSS v3.1 Base Score: 5.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Local Denial-of-Service Vulnerability in HPE 
Networking EdgeConnect SD-WAN Gateways
  (CVE-2026-76702)
  -----------------------------------------------------------------
    A vulnerability in the operating system of HPE Networking 
    EdgeConnect SD-WAN Gateways could allow an authenticated local 
    attacker to cause a denial-of-service. Successful exploitation 
    could allow an attacker to disrupt system operations, 
    potentially resulting in an unstable system state.
 
    Internal References: VULN-683
    Severity: Medium
    CVSS v3.1 Base Score: 5.8
    CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Buffer Overflow Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes 
Denial-of-Service
(CVE-2026-76703)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in the web-based management
    interface of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an authenticated attacker with administrative access to cause 
    a denial of service. Successful exploitation could allow an attacker 
    to disrupt system operations, potentially resulting in an unstable 
    system state.
 
    Internal References: VULN-639
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in 
EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
(CVE-2026-76704)
  -----------------------------------------------------------------
    A vulnerability in the web-based management interface of the
    EdgeConnect SD-WAN Orchestrator could allow an authenticated 
    remote attacker to execute arbitrary script code in a victim's 
    browser in the context of the affected interface. Successful 
    exploitation could allow an attacker to access sensitive 
    information, potentially affecting the confidentiality and 
    integrity of the data processed by the application.
 
    Internal References: VULN-69
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
 
    Acknowledgements: m0x_noob (HPE Networking's Bug Bounty program).


Authenticated Buffer Overflow Vulnerability in an API Endpoint 
Leads to Remote Code Execution in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76705)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways. Successful 
    exploitation could allow an authenticated remote attacker with
    Admin privilege to execute arbitrary commands on the underlying 
    operating system.
 
    Internal References: VULN-704
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Unauthenticated Information Disclosure in EdgeConnect SD-WAN 
Orchestrator API allows exposure of sensitive data
(CVE-2026-76706)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Orchestrator could allow an unauthenticated 
    remote attacker to obtain sensitive information. Successful 
    exploitation could result in the disclosure of security-relevant 
    configuration details and security feature status, which could 
    be used to facilitate further attacks.
 
    Internal References: VULN-678
    Severity: Medium
    CVSS v3.1 Base Score: 5.3
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).


Limited Buffer Overflow in Suricata
(CVE-2024-32664)
  -----------------------------------------------------------
    A vulnerability in Suricata could allow specially crafted 
    network traffic or datasets to cause a limited buffer 
    overflow. This vulnerability affects Suricata versions 
    prior to 7.0.5 and 6.0.19 and is resolved in versions 7.0.5 
    and 6.0.19. As a workaround, avoid using rules containing 
    the base64_decode keyword with the bytes option set to a 
    value of 1, 2, or 5. For Suricata 7.0.x, additionally set 
    app-layer.protocols.smtp.mime.body-md5 to false.
 
    Internal References: VULN-66 
    Severity: Medium 
    CVSS v3.1 Base Score: 5.3 
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 
 
    Acknowledgements: Evgeny Legerov of Kaspersky Lab.
 
    NOTE: For additional information, please refer to the following link: 
    https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7 
    

Unauthenticated Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76707)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to view some
    system memory contents. Successful exploitation could allow an
    attacker to gain insight into internal services and workflows,
    increasing the risk of unauthorized access and elevated 
    privileges when combined with other vulnerabilities.

    Internal References: VULN-711
    Severity: Medium
    CVSS v3.1 Base Score: 4.3
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

    Acknowledgements: Internal security research (HPE Networking).


References 
==========
CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, 
CVE-2026-76673, CVE-2026-76674,	CVE-2026-76675, 
CVE-2026-76676, CVE-2026-76677,	CVE-2026-76678, 
CVE-2026-76679, CVE-2026-76680, CVE-2026-76681, 
CVE-2026-76682, CVE-2026-76683, CVE-2026-76684, 
CVE-2026-76685, CVE-2026-76686,	CVE-2026-76687, 
CVE-2026-76688, CVE-2026-76689, CVE-2026-76690, 
CVE-2026-76691, CVE-2026-76692,	CVE-2026-76693, 
CVE-2026-76694, CVE-2026-76695,	CVE-2026-76696, 
CVE-2026-76697, CVE-2026-76698,	CVE-2026-76699, 
CVE-2026-76700, CVE-2026-76701, CVE-2026-76702, 
CVE-2026-76703, CVE-2026-76704, CVE-2026-76705, 
CVE-2026-76706, CVE-2024-32664, CVE-2026-76707.

-----BEGIN PGP SIGNATURE-----

iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmqoaxkXHHNlY3VyaXR5
LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A72kwv/VIPTILnenfCLc7NqJdri65Yk
gQ8Y8n+8UwhI9RGxqVcz2xhn0Q31ng5RXyrndPLpSHAKLvKaKEom7Bcn3FLElqiP
vBK9ttNO7xebcYUm2iq8dEO2/w6mkaXeffqHlobys/QLsHc3ZT3apbKg82rCKpGe
w0NmiGh8Mq04Rr0oyWNcqvNp2sbOlP8l4eDiKpQ5MSy+27pgOVaZ8UPTYi1TQvhs
1eGc8gw+yGk1C5TA1NOg71AmwL/5Zi8nJMECDW0M7ao1wh3oJOWsOv9rsgpPtJzC
1yVmgUQ8pcw7vvHkVJVBj5GAiURmdONHbuoi8f0Gwsa/Bui756z5n8neyq3ULeWM
1Ywp0ZEsgD85NTyRaRwA5AXMuKzgOa+q1KXZblFXjmq/z8c6YH+Dsck69+bkhDyz
/SduBeX3cN5ZvjA5uQl7weQKbJaUJt3hecSoouvcZFktAeYIX220oHvgHaMoY/yL
U3ZnF73NWswIlCnWpOk+99bSK9JJOkD/h0kyivkl
=9CdE
=======
    service.
 
    Internal References: VULN-640, VULN-654, VULN-656, VULN-648
    Severity: Medium
    CVSS v3.1 Base Score: 5.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Unauthenticated Sensitive Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76701)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Gateways could allow an unauthenticated 
    remote attacker to access sensitive information. Successful 
    exploitation could allow an attacker to retrieve information 
    which could be used to potentially gain further access to 
    network services supported by HPE Networking EdgeConnect 
    SD-WAN Gateways.
 
    Internal References: VULN-645
    Severity: Medium
    CVSS v3.1 Base Score: 5.9
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Local Denial-of-Service Vulnerability in HPE 
Networking EdgeConnect SD-WAN Gateways
  (CVE-2026-76702)
  -----------------------------------------------------------------
    A vulnerability in the operating system of HPE Networking 
    EdgeConnect SD-WAN Gateways could allow an authenticated local 
    attacker to cause a denial-of-service. Successful exploitation 
    could allow an attacker to disrupt system operations, 
    potentially resulting in an unstable system state.
 
    Internal References: VULN-683
    Severity: Medium
    CVSS v3.1 Base Score: 5.8
    CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 
    
Authenticated Buffer Overflow Vulnerability in HPE Networking 
EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes 
Denial-of-Service
(CVE-2026-76703)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in the web-based management
    interface of HPE Networking EdgeConnect SD-WAN Gateways that could 
    allow an authenticated attacker with administrative access to cause 
    a denial of service. Successful exploitation could allow an attacker 
    to disrupt system operations, potentially resulting in an unstable 
    system state.
 
    Internal References: VULN-639
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).
 

Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in 
EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
(CVE-2026-76704)
  -----------------------------------------------------------------
    A vulnerability in the web-based management interface of the
    EdgeConnect SD-WAN Orchestrator could allow an authenticated 
    remote attacker to execute arbitrary script code in a victim's 
    browser in the context of the affected interface. Successful 
    exploitation could allow an attacker to access sensitive 
    information, potentially affecting the confidentiality and 
    integrity of the data processed by the application.
 
    Internal References: VULN-69
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
 
    Acknowledgements: m0x_noob (HPE Networking's Bug Bounty program).


Authenticated Buffer Overflow Vulnerability in an API Endpoint 
Leads to Remote Code Execution in HPE Networking EdgeConnect 
SD-WAN Gateways
(CVE-2026-76705)
  -----------------------------------------------------------------
    A buffer overflow vulnerability exists in the API endpoint of 
    HPE Networking EdgeConnect SD-WAN Gateways. Successful 
    exploitation could allow an authenticated remote attacker with
    Admin privilege to execute arbitrary commands on the underlying 
    operating system.
 
    Internal References: VULN-704
    Severity: Medium
    CVSS v3.1 Base Score: 5.5
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
 
    Acknowledgements: Internal security research (HPE Networking).

    
Unauthenticated Information Disclosure in EdgeConnect SD-WAN 
Orchestrator API allows exposure of sensitive data
(CVE-2026-76706)
  -----------------------------------------------------------------
    A vulnerability in the API endpoint of HPE Networking
    EdgeConnect SD-WAN Orchestrator could allow an unauthenticated 
    remote attacker to obtain sensitive information. Successful 
    exploitation could result in the disclosure of security-relevant 
    configuration details and security feature status, which could 
    be used to facilitate further attacks.
 
    Internal References: VULN-678
    Severity: Medium
    CVSS v3.1 Base Score: 5.3
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
 
    Acknowledgements: Internal security research (HPE Networking).


Limited Buffer Overflow in Suricata
(CVE-2024-32664)
  -----------------------------------------------------------
    A vulnerability in Suricata could allow specially crafted 
    network traffic or datasets to cause a limited buffer 
    overflow. This vulnerability affects Suricata versions 
    prior to 7.0.5 and 6.0.19 and is resolved in versions 7.0.5 
    and 6.0.19. As a workaround, avoid using rules containing 
    the base64_decode keyword with the bytes option set to a 
    value of 1, 2, or 5. For Suricata 7.0.x, additionally set 
    app-layer.protocols.smtp.mime.body-md5 to false.
 
    Internal References: VULN-66 
    Severity: Medium 
    CVSS v3.1 Base Score: 5.3 
    CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 
 
    Acknowledgements: Evgeny Legerov of Kaspersky Lab.
 
    NOTE: For additional information, please refer to the following link: 
    https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7 
    

Unauthenticated Information Disclosure in HPE Networking 
EdgeConnect SD-WAN Gateways
(CVE-2026-76707)
  -----------------------------------------------------------------
    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
    could allow an unauthenticated adjacent attacker to view some
    system memory contents. Successful exploitation could allow an
    attacker to gain insight into internal services and workflows,
    increasing the risk of unauthorized access and elevated 
    privileges when combined with other vulnerabilities.

    Internal References: VULN-711
    Severity: Medium
    CVSS v3.1 Base Score: 4.3
    CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

    Acknowledgements: Internal security research (HPE Networking).


References 
==========
CVE-2026-76669, CVE-2026-76670, CVE-2026-76671, 
CVE-2026-76672, CVE-2026-76673, CVE-2026-76674,	
CVE-2026-76675, CVE-2026-76676, CVE-2026-76677,	
CVE-2026-76678, CVE-2026-76679, CVE-2026-76680, 
CVE-2026-76681, CVE-2026-76682, CVE-2026-76683, 
CVE-2026-76684, CVE-2026-76685, CVE-2026-76686,			
CVE-2026-76687, CVE-2026-76688, CVE-2026-76689,
CVE-2026-76690, CVE-2026-76691, CVE-2026-76692,	
CVE-2026-76693, CVE-2026-76694, CVE-2026-76695,	
CVE-2026-76696, CVE-2026-76697, CVE-2026-76698,			
CVE-2026-76699, CVE-2026-76700, CVE-2026-76701,
CVE-2026-76702, CVE-2026-76703, CVE-2026-76704,
CVE-2026-76705, CVE-2026-76706, CVE-2024-32664, 
CVE-2026-76707.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




