Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2024-42394CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.6%CVE-2026-44878HIGHAuthenticated Path Traversal allows Unauthorized Access in Web InterfaceEPSS 0.6%CVE-2025-23059MEDIUMSensitive Information Disclosure in HPE Aruba Networking ClearPass Policy ManagerEPSS 0.6%CVE-2026-76708CRITICALUnauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.6%CVE-2026-76709CRITICALUnauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.6%CVE-2023-22777MEDIUMAuthenticated Information Disclosure in ArubaOS Web-based Management InterfaceEPSS 0.6%CVE-2026-76683HIGHUnauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2026-44864HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.6%CVE-2026-44863HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.6%CVE-2026-44862HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.6%CVE-2026-44861HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.6%CVE-2026-44860HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.6%CVE-2023-22775MEDIUMAuthenticated Sensitive Information Disclosure in ArubaOS Command Line InterfaceEPSS 0.6%CVE-2023-30510MEDIUMAuthenticated Server-side Request Forgery in Aruba EdgeConnect Enterprise Web Management InterfaceEPSS 0.6%CVE-2023-43510MEDIUMAuthenticated Remote Command Injection in ClearPass Policy Manager Web-Based Management Interface Leading to Partial System CompromiseEPSS 0.6%CVE-2026-73786HIGHUnauthenticated Network-Based Denial of Service in CPPM systemsEPSS 0.6%CVE-2026-76686HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.6%CVE-2026-73715HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric ComposerEPSS 0.6%CVE-2024-31481MEDIUMUnauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.6%CVE-2024-31480MEDIUMUnauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.6%