Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2024-25615MEDIUM An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. SuccEPSS 0.5%CVE-2026-76687HIGHAuthenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2025-37166HIGHUnexpected shutdown in HPE Instant On Access Points after processing specific packetsEPSS 0.5%CVE-2026-76711HIGHUnauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.5%CVE-2023-35978MEDIUMReflected Cross-Site Scripting (XSS) in ArubaOS Web-based Management InterfaceEPSS 0.5%CVE-2022-43526MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2022-43525MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2022-43527MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2026-73775HIGHAuthenticated Sensitive Information Disclosure Vulnerabilities in AOS-CXEPSS 0.5%CVE-2026-73773HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CXEPSS 0.5%CVE-2024-51772MEDIUMAuthenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)EPSS 0.5%CVE-2026-44877MEDIUMUnauthenticated Remote Disclosure of Cryptographic SecretsEPSS 0.5%CVE-2026-76679HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2023-25594MEDIUMAuthorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.5%CVE-2026-73710HIGHUnauthenticated Denial of Service Vulnerabilities in API Endpoint of HPE Networking Fabric ComposerEPSS 0.5%CVE-2025-37123HIGHAuthenticated Command Injection leads to Unauthorized Actions in CLI InterfaceEPSS 0.5%CVE-2026-73711HIGHUnauthenticated Privilege Escalation allows Administrative Access in HPE Networking Fabric Composer APIEPSS 0.5%CVE-2026-73706HIGHAuthentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure and Unauthorized ChangesEPSS 0.5%CVE-2026-73777HIGHAuthorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API EndpointEPSS 0.5%CVE-2026-76684HIGHAuthentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.5%