{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Networking has released patches for the HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator that address multiple security vulnerabilities.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect the following HPE Networking EdgeConnect SD-WAN software versions unless specifically noted otherwise in the details section:\n\nHPE Networking EdgeConnect SD-WAN Gateways\n  - ECOS 9.7.x.x: 9.7.0.0 and below\n  - ECOS 9.6.x.x: 9.6.3.1 and below\n  - ECOS 9.5.x.x: 9.5.8.1 and below\n  - ECOS 9.4.x.x: 9.4.8.2 and below\n\nHPE Networking EdgeConnect SD-WAN Orchestrator:\n    - Orchestrator 9.7.x: 9.7.0 and below\n    - Orchestrator 9.6.x: 9.6.3 and below\n    - Orchestrator 9.5.x: 9.5.8 and below\n    - Orchestrator 9.4.x: 9.4.10 and below",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products and software versions not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "These vulnerabilities were generally discovered by internal security research at HPE Networking. HPE Networking is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory. Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at:\nhttps://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us\n \nFor reporting *NEW* HPE Networking security issues, email can be sent to networking-sirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at:\nhttps://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: networking-psirt(at)hpe.com - For further details please see http://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported. A security vulnerability is defined as any weakness in a product that allows an attacker to compromise the confidentiality, integrity, or availability of a product, customer infrastructure, or IT system through an HPE Aruba Networking product in that environment.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "summary": "HPE Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator",
    "tracking": {
      "current_release_date": "2026-09-15T16:00:00.000Z",
      "generator": {
        "date": "2026-09-15T18:18:12.052Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "HPESBNW05135",
      "initial_release_date": "2026-09-15T16:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-15T16:00:00.000Z",
          "number": "1",
          "summary": "Initial release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "ECOS 9.7.1.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": "ECOS 9.7.1.0"
                }
              },
              {
                "category": "product_version",
                "name": "ECOS 9.6.4.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": "ECOS 9.6.4.0"
                }
              },
              {
                "category": "product_version",
                "name": "ECOS 9.5.9.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": "ECOS 9.5.9.0"
                }
              },
              {
                "category": "product_version",
                "name": "ECOS 9.4.9.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": "ECOS 9.4.9.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.7.0.0|<=9.7.0.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": ">=9.7.0.0|<=9.7.0.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.6.0.0|<=9.6.3.1",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": ">=9.6.0.0|<=9.6.3.1"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.5.0.0|<=9.5.8.1",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": ">=9.5.0.0|<=9.5.8.1"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.4.0.0|<=9.4.8.2",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Gateways",
                  "product_id": ">=9.4.0.0|<=9.4.8.2"
                }
              }
            ],
            "category": "product_name",
            "name": "EdgeConnect SD-WAN Gateways"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "Orchestrator 9.7.1",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": "Orchestrator 9.7.1"
                }
              },
              {
                "category": "product_version",
                "name": "Orchestrator 9.6.4",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": "Orchestrator 9.6.4"
                }
              },
              {
                "category": "product_version",
                "name": "Orchestrator 9.5.9",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": "Orchestrator 9.5.9"
                }
              },
              {
                "category": "product_version",
                "name": "Orchestrator 9.4.11",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": "Orchestrator 9.4.11"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.7.0|<=9.7.0",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": ">=9.7.0|<=9.7.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.6.0|<=9.6.3",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": ">=9.6.0|<=9.6.3"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.5.0|<=9.5.8",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": ">=9.5.0|<=9.5.8"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=9.4.0|<=9.4.10",
                "product": {
                  "name": "HPE Networking EdgeConnect SD-WAN Orchestrator",
                  "product_id": ">=9.4.0|<=9.4.10"
                }
              }
            ],
            "category": "product_name",
            "name": "EdgeConnect SD-WAN Orchestrator"
          }
        ],
        "category": "vendor",
        "name": "HPE Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76670",
      "notes": [
        {
          "category": "details",
          "text": "Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-661, VULN-664, VULN-669, VULN-670",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 10,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 9.9,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Christopher Alejandro (Moroco)"
          ],
          "summary": "These vulnerabilities were also discovered and reported by Christopher Alejandro (Moroco)."
        }
      ],
      "cve": "CVE-2026-76669",
      "notes": [
        {
          "category": "details",
          "text": "Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-661, VULN-664, VULN-669, VULN-670",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 10,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 9.9,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76672",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-677",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.9,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 9.9,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76673",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-659, VULN-660",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76674",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-680, VULN-681",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76675",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-693",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.1,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "temporalScore": 9.1,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76676",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-686, VULN-698",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76677",
      "notes": [
        {
          "category": "details",
          "text": "A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-671",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authorization Bypass Leading to Privilege Escalation in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76678",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-707, VULN-708",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76679",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-650, VULN-651, VULN-655, VULN-682, VULN-687, VULN-688, VULN-689, VULN-691, VULN-695, VULN-706",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 8.6,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "temporalScore": 8.6,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76680",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-672, VULN-675",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 8.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76681",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by EdgeConnect SD-WAN Orchestrator.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-673, VULN-674, VULN-676",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 8.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator API"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76682",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticated remote attacker to exploit a limited buffer overflow. Successful exploitation could allow an attacker to cause a denial-of-service or potentially execute arbitrary code on the system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-643, VULN-652, VULN-697, VULN-705",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 8.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76683",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-641, VULN-644",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76684",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-662, VULN-663",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator API"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76685",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer overflow. Successful exploitation could result in a buffer overflow, potentially leading to remote code execution or denial-of-service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-709",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76686",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-634, VULN-635, VULN-636, VULN-684, VULN-685, VULN-696",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76687",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-668",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76688",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD-WAN Orchestrator host.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-665, VULN-666",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect SD-WAN Orchestrator"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76689",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution with root privileges or a denial of service due to a system crash.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-637",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76690",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-642, VULN-701",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Remote Code Execution Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76691",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-692, VULN-699, VULN-703",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API Endpoint"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76692",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-710, VULN-712, VULN-694",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 7.1,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.1,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Adjacent Information Disclosure and Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76693",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-638, VULN-653",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 7,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76694",
      "notes": [
        {
          "category": "details",
          "text": "A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-646",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.6,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 6.6,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Privilege Escalation Vulnerability in the Command Line Interface of HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76695",
      "notes": [
        {
          "category": "details",
          "text": "Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-657, VULN-658, VULN-690",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76696",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-679",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76697",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-700",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76698",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-702",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Command Injection Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76699",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-713",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76700",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-640, VULN-654, VULN-656, VULN-648",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.9,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.9,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76701",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-645",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 5.9,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.9,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76702",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-683",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.8,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 5.8,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Local Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76703",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-639",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 5.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Buffer Overflow Vulnerability in HPE Networking EdgeConnect SD-WAN Gateways Web-Based Management Interface Causes Denial-of-Service"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "m0x_noob"
          ],
          "organization": "HPE Networking Bug Bounty Program",
          "summary": "This vulnerability was discovered and reported by m0x_noob through HPE Networking's Bug Bounty program."
        }
      ],
      "cve": "CVE-2026-76704",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidentiality and integrity of the data processed by the application.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-69",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "temporalScore": 5.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Authenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76705",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-704",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 5.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Authenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76706",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-678",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "Orchestrator 9.7.1",
          "Orchestrator 9.6.4",
          "Orchestrator 9.5.9",
          "Orchestrator 9.4.11"
        ],
        "known_affected": [
          ">=9.7.0|<=9.7.0",
          ">=9.6.0|<=9.6.3",
          ">=9.5.0|<=9.5.8",
          ">=9.4.0|<=9.4.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking SD-WAN Orchestrator to the following software versions (as applicable):\n\n    - Orchestrator 9.7.1 and above\n    - Orchestrator 9.6.4 and above\n    - Orchestrator 9.5.9 and above\n    - Orchestrator 9.4.11 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "Orchestrator 9.7.1",
            "Orchestrator 9.6.4",
            "Orchestrator 9.5.9",
            "Orchestrator 9.4.11"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0|<=9.7.0",
            ">=9.6.0|<=9.6.3",
            ">=9.5.0|<=9.5.8",
            ">=9.4.0|<=9.4.10"
          ]
        }
      ],
      "title": "Unauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive data"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Evgeny Legerov"
          ],
          "organization": "Kaspersky Lab",
          "summary": "This vulnerability was discovered by Evgeny Legerov of Kaspersky Lab."
        }
      ],
      "cve": "CVE-2024-32664",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in Suricata could allow specially crafted network traffic or datasets to cause a limited buffer overflow. This vulnerability affects Suricata versions prior to 7.0.5 and 6.0.19 and is resolved in versions 7.0.5 and 6.0.19. As a workaround, avoid using rules containing the base64_decode keyword with the bytes option set to a value of 1, 2, or 5. For Suricata 7.0.x, additionally set app-layer.protocols.smtp.mime.body-md5 to false.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-66",
          "title": "Internal References"
        },
        {
          "category": "other",
          "text": "For additional information, please refer to the following link: https://github.com/OISF/suricata/security/advisories/GHSA-79vh-hpwq-3jh7",
          "title": "Note"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "Avoid using rules containing the base64_decode keyword with the bytes option set to a value of 1, 2, or 5. For Suricata 7.0.x, additionally set app-layer.protocols.smtp.mime.body-md5 to false.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Limited Buffer Overflow in Suricata"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking",
          "summary": "These vulnerabilities were discovered by internal security research at HPE Networking."
        }
      ],
      "cve": "CVE-2026-76707",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabilities.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-711",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "ECOS 9.7.1.0",
          "ECOS 9.6.4.0",
          "ECOS 9.5.9.0",
          "ECOS 9.4.9.0"
        ],
        "known_affected": [
          ">=9.7.0.0|<=9.7.0.0",
          ">=9.6.0.0|<=9.6.3.1",
          ">=9.5.0.0|<=9.5.8.1",
          ">=9.4.0.0|<=9.4.8.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking EdgeConnect SD-WAN Gateways to the following software versions (as applicable):\n\n    - ECOS 9.7.1.0 and above\n    - ECOS 9.6.4.0 and above\n    - ECOS 9.5.9.0 and above\n    - ECOS 9.4.9.0 and above\n\nIMPORTANT: The HPE Networking EdgeConnect SD-WAN Orchestrator software version must be greater than or equal to the ECOS software version running on any HPE Networking EdgeConnect SD-WAN Gateways.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.\n\nFor more details on HPE Networking's End-of-Support policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf",
          "product_ids": [
            "ECOS 9.7.1.0",
            "ECOS 9.6.4.0",
            "ECOS 9.5.9.0",
            "ECOS 9.4.9.0"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-09-15T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 4.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 4.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=9.7.0.0|<=9.7.0.0",
            ">=9.6.0.0|<=9.6.3.1",
            ">=9.5.0.0|<=9.5.8.1",
            ">=9.4.0.0|<=9.4.8.2"
          ]
        }
      ],
      "title": "Unauthenticated Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways"
    }
  ]
}