Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-76700MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-76697MEDIUMAuthenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management InterfaceEPSS 0.5%CVE-2025-37145MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2025-37144MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2024-31474HIGHThere is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). SuccessfulEPSS 0.4%CVE-2024-31475HIGHThere is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management prEPSS 0.4%CVE-2025-37168HIGHUnauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating SystemEPSS 0.4%CVE-2025-27078MEDIUMAuthenticated Remote Command Execution caused by Insecure Function Usage in System BinaryEPSS 0.4%CVE-2023-22771MEDIUMInsufficient Session Expiration in ArubaOS Command Line InterfaceEPSS 0.4%CVE-2026-73783MEDIUMAuthenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CXEPSS 0.4%CVE-2026-76712HIGHUnauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-38484HIGHMultiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and GatewaysEPSS 0.4%CVE-2025-37173HIGHImproper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)EPSS 0.4%CVE-2022-43529MEDIUMA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persistEPSS 0.4%CVE-2024-22436MEDIUMA security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.EPSS 0.4%CVE-2026-73700CRITICALAuthenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.4%CVE-2024-6206HIGHA security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerabiliEPSS 0.4%CVE-2022-43532HIGH A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct aEPSS 0.4%CVE-2026-73736MEDIUMUnauthenticated Limited Information Disclosure leads to Data Exposure in HPE Networking Fabric ComposerEPSS 0.4%CVE-2026-73728MEDIUMAuthenticated Denial of Service Vulnerabilities in HPE Networking Fabric Composer APIEPSS 0.4%