Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-76669CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2023-30911MEDIUMHPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service.EPSS 0.5%CVE-2026-76670CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2021-46846MEDIUMCross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5. EPSS 0.5%CVE-2024-22441CRITICALHPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.EPSS 0.5%CVE-2023-37425HIGHUnauthenticated Stored Cross-Site Scripting Vulnerability (XSS) in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.5%CVE-2022-37926MEDIUMA vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-EPSS 0.5%CVE-2023-37439MEDIUMReflected Cross Site Scripting in EdgeConnect SD-WAN Orchestrator Web Management InterfaceEPSS 0.5%CVE-2026-76695MEDIUMUnauthenticated Buffer Overflow Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2025-37100HIGHExposure of Sensitive Information to an Unauthorized User in HPE Aruba Networking Private 5G CoreEPSS 0.5%CVE-2026-73763HIGHUnauthenticated Remote Command Execution in Management ComponentEPSS 0.5%CVE-2023-22778MEDIUMAuthenticated Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-25593HIGHReflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.5%CVE-2023-25592HIGHReflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.5%CVE-2023-37426HIGHShared SSH Static Host Keys in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2026-73771HIGHImproper Authentication Handling in AOS-CX Management Interface and APIEPSS 0.5%CVE-2025-37182HIGHAuthenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.5%CVE-2025-37183HIGHAuthenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.5%CVE-2025-37181HIGHAuthenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.5%CVE-2026-73752HIGHUnauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CXEPSS 0.5%