HPE EdgeConnect Fixes Reach Into the Control Plane
HPE disclosed 39 vulnerabilities in EdgeConnect SD-WAN, including six critical issues that affect both Networking EdgeConnect SD-WAN Gateways and the Orchestrator across the 9.4.x to 9.7.x branches. INCIBE-CERT says the risky builds include older ECOS gateway releases and matching Orchestrator versions in the same trains.
Some of the flaws let a low-privileged or unauthenticated requester send a crafted API call that the product mishandles, turning it into admin access, privilege escalation, or code execution. In one case, an authenticated read-only user could pull sensitive configuration data, including API tokens and third-party credentials, from the Orchestrator cache-sync endpoint.
That puts the management plane and the edge boxes in the same exposure chain: if the Orchestrator is compromised, the attacker can reach fleet-wide configuration and credentials, while Gateway flaws can land code execution at the edge. HPE also says the Orchestrator version must be at least as new as the ECOS version on any managed gateway, so mixed estates inherit a patch-coordination problem, not just a software-update problem.
Rilasciati aggiornamenti di sicurezza per risolvere 39 vulnerabilità, di cui 6 con gravità "critica" e 18 con gravità "alta", che interessano i prodotti HPE Networking EdgeConnect SD-WAN Gateways e Orchestrator