Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-22772MEDIUMAuthenticated Path Traversal in ArubaOS Web-based Management Interface Allows for Arbitrary File DeletionEPSS 0.7%CVE-2026-76657CRITICALAuthentication Bypass in HPE Networking Fabric Composer API allows Administrative AccessEPSS 0.7%CVE-2026-23813CRITICALAuthentication Bypass in Web Interface allows Unauthenticated Admin Password ResetEPSS 0.7%CVE-2025-23058HIGHAuthenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.7%CVE-2022-43518MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnEPSS 0.7%CVE-2022-44532MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of EPSS 0.7%CVE-2026-23593HIGHUnauthenticated Limited File Read allows Data Exposure in Web InterfaceEPSS 0.7%CVE-2023-35975MEDIUMAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File DeletionEPSS 0.7%CVE-2024-53673HIGHA java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.EPSS 0.7%CVE-2022-37919HIGHA vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based EPSS 0.7%CVE-2022-37937CRITICALPre-auth memory corruption in HPE ServiceguardEPSS 0.7%CVE-2025-23051HIGHAuthenticated Remote Code Execution in AOS Web-based Management InterfaceEPSS 0.7%CVE-2019-5398—A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 0.7%CVE-2023-22776MEDIUMAuthenticated Remote Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File ReadEPSS 0.7%CVE-2024-33519HIGHAuthenticated Server-Side prototype pollution Leading to Information DisclosureEPSS 0.7%CVE-2026-76682HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.7%CVE-2023-45617HIGHThere are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). SuccessfulEPSS 0.7%CVE-2023-45619HIGHThere is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). SuccessfuEPSS 0.7%CVE-2023-45618HIGHThere are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol).EPSS 0.7%CVE-2024-41134HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.7%