Vulnerabilities in Hewlett Packard Enterprise (HPE)

598 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-43506HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2026-73737MEDIUMUnauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File ModificationEPSS 0.2%CVE-2025-37104HIGHHPE Telco Service Orchestrator Software, Authenticated SQL InjectionEPSS 0.2%CVE-2023-38402HIGHArbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows ClientEPSS 0.2%CVE-2022-37935MEDIUMHPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.EPSS 0.2%CVE-2026-73780HIGHLack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CXEPSS 0.2%CVE-2025-37109LOWHPE Telco Service Activator, Protection Mechanism FailureEPSS 0.2%CVE-2025-37108LOWHPE Telco Service Activator, Protection Mechanism FailureEPSS 0.2%CVE-2025-27080MEDIUMAuthenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2023-28091MEDIUMHPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dumpEPSS 0.2%CVE-2022-37939LOWA potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locaEPSS 0.2%CVE-2025-27087MEDIUMA vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.EPSS 0.2%CVE-2026-73768HIGHLocal Privilege Escalation in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2024-54009MEDIUMRemote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited EPSS 0.2%CVE-2026-23810MEDIUMCross-BSSID GTK Re-encryption and Traffic InjectionEPSS 0.2%CVE-2023-28085MEDIUMAn HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentialsEPSS 0.2%CVE-2022-43535HIGHA vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. AEPSS 0.2%CVE-2023-25590HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2023-30903—HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. EPSS 0.2%CVE-2022-43540MEDIUMA vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtaEPSS 0.2%