Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2022-37938CRITICALUnauthenticated server side request forgery in HPE Serviceguard ManagerEPSS 0.6%CVE-2026-44858HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-63453HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.6%CVE-2026-44855HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44859HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44857HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2026-44856HIGHAuthenticated Stack-Based Buffer Overflow in PAPI ServicesEPSS 0.6%CVE-2025-37090MEDIUMA server-side request forgery vulnerability exists in HPE StoreOnce Software.EPSS 0.6%CVE-2023-35971HIGHUnauthenticated Stored Cross-Site Scripting (XSS) in ArubaOS Web-based Management InterfaceEPSS 0.6%CVE-2024-33515MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.6%CVE-2024-33514MEDIUMUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploiEPSS 0.6%CVE-2024-33517MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. SucceEPSS 0.6%CVE-2024-33516MEDIUMAn unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. SucEPSS 0.6%CVE-2026-23821HIGHInconsistent input filtering allows Authenticated Command Injection in AOS-10 CLIEPSS 0.6%CVE-2026-73705HIGHAuthenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.6%CVE-2026-44852HIGHAuthenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management InterfaceEPSS 0.6%CVE-2023-50272HIGHA potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulneEPSS 0.6%CVE-2025-27085MEDIUMArbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility ConductorEPSS 0.6%CVE-2023-25591HIGHAuthenticated Information Disclosure in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.6%CVE-2026-76673CRITICALAuthentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN OrchestratorEPSS 0.6%