Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-45620HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.9%CVE-2023-45622HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the BLE daemon service accessed via the PAPI protocol. Successful exploitatEPSS 0.9%CVE-2023-45623HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitEPSS 0.9%CVE-2026-63454HIGHAuthenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CXEPSS 0.9%CVE-2023-45621HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.9%CVE-2026-73765HIGHAuthenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CXEPSS 0.9%CVE-2023-45624HIGHAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitatioEPSS 0.9%CVE-2023-37424HIGHUnauthenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.9%CVE-2025-37094MEDIUMA directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.EPSS 0.9%CVE-2026-76689HIGHAuthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.9%CVE-2023-22787HIGHUnauthenticated Denial of Service (DoS) in Aruba InstantOS or ArubaOS 10 Service Accessed via the PAPI ProtocolEPSS 0.8%CVE-2026-76714HIGHAuthenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.8%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-73717HIGHUnauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.8%CVE-2026-73749CRITICALUnauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%CVE-2022-43531HIGH Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SEPSS 0.8%CVE-2023-45627MEDIUMAn authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in tEPSS 0.8%CVE-2026-73750HIGHAuthenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code ExecutionEPSS 0.8%CVE-2026-63456CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.8%CVE-2023-43507HIGHAuthenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management InterfaceEPSS 0.8%