Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-73701CRITICALUnauthenticated Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.7%CVE-2026-76685HIGHUnauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.7%CVE-2026-73751HIGHAuthenticated Remote Command Injection in AOS-CX Web-based Management InterfaceEPSS 0.7%CVE-2026-73753HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 0.7%CVE-2025-37138MEDIUMAuthenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)EPSS 0.7%CVE-2025-37157MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-37158MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-37184CRITICALUnauthenticated Bypass Allows Multi-Factor Authentication CircumventionEPSS 0.7%CVE-2026-73719HIGHAuthenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.7%CVE-2023-30508MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2023-30509MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2023-30507MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2025-25039MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.6%CVE-2026-73712HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric Composer APIEPSS 0.6%CVE-2025-37126HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line InterfaceEPSS 0.6%CVE-2026-73716HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.6%CVE-2023-35979MEDIUMUnauthenticated Buffer Overflow Vulnerability in ArubaOS Web-Based Management InterfaceEPSS 0.6%CVE-2024-42393CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.6%CVE-2026-76678HIGHAuthenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2024-22442CRITICALThe vulnerability could be remotely exploited to bypass authentication.EPSS 0.6%