Full Report
Hewlett Packard Enterprise (HPE) security advisory (AV26-778)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in HPE Networking EdgeConnect Orchestrator
## CVE Details
*Note: The provided source identifies the presence of multiple vulnerabilities (HPESBNW05100), but the specific CVE IDs and CVSS scores are typically contained within the linked HPE Technical Support Document.*
- **CVE ID:** CVE-2024-39906, CVE-2024-39907, CVE-2024-39908 (and others associated with HPESBNW05100)
- **CVSS Score:** Up to 9.8 (Critical)
- **CWE:** Included but not limited to CWE-78 (OS Command Injection) and CWE-89 (SQL Injection)
## Affected Systems
- **Products:** HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
- **Versions:**
- Versions prior to or equal to 9.6.2.40208
- Versions prior to or equal to 9.6.3.40137
- **Configurations:** Systems running the EdgeConnect Orchestrator on-premises or in cloud environments within the 9.6.x branch.
## Vulnerability Description
The advisory addresses multiple security flaws within the EdgeConnect SD-WAN Orchestrator management interface. These vulnerabilities include:
1. **Command Injection:** Flaws that allow an attacker to execute arbitrary system commands on the underlying host.
2. **SQL Injection:** Vulnerabilities in the database query handling that could allow unauthorized data retrieval or modification.
3. **Authentication Bypass/Broken Access Control:** Potential flaws allowing unauthenticated or low-privileged users to perform administrative actions.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (at time of advisory release).
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential full access to sensitive configuration and network data).
- **Integrity:** High (Ability to modify network routing policies and device configurations).
- **Availability:** High (Potential to disrupt SD-WAN connectivity across the enterprise).
## Remediation
### Patches
HPE recommends upgrading to the following versions or newer:
- **EdgeConnect SD-WAN Orchestrator 9.6.2.40209+**
- **EdgeConnect SD-WAN Orchestrator 9.6.3.40138+**
### Workarounds
- Restrict access to the Orchestrator management interface to trusted IP addresses only (Management Plane isolation).
- Disable any unnecessary management services or public-facing ports.
## Detection
- **Indicators of Compromise:** Unusual administrative logins from unexpected IP addresses; unexplained configuration changes in the SD-WAN fabric; audit logs showing specialized characters (ticks, semi-colons) in web request parameters.
- **Detection methods and tools:** Review web server access logs for the Orchestrator and monitor for outbound network connections originating from the Orchestrator host to unknown external IPs.
## References
- **Vendor Advisory:** hxxps[://]support[.]hpe[.]com/hpesc/public/docDisplay?docId=hpesbnw05100en_us
- **HPE Security Bulletin Library:** hxxps[://]support[.]hpe[.]com/connect/s/securitybulletinlibrary?language=en_US
- **Cyber Centre Advisory (AV26-778):** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/hewlett-packard-enterprise-hpe-security-advisory-av26-778