Vulnerabilities in Hewlett Packard Enterprise (HPE)

459 results
Vexday analysis

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2024-31473CRITICALThere is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code executiEPSS 1.7%CVE-2026-44879HIGHAuthenticated Command Injection allows arbitrary command execution in CLI InterfaceEPSS 1.7%CVE-2023-3718HIGHAuthenticated Command Injection Vulnerability in AOS-CX Command Line InterfaceEPSS 1.6%CVE-2019-5404A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1EPSS 1.6%CVE-2023-22758HIGHAuthenticated Remote Command Execution in ArubaOS Web-based Management InterfaceEPSS 1.6%CVE-2023-22760HIGHAuthenticated Remote Command Execution in ArubaOS Web-based Management InterfaceEPSS 1.6%CVE-2023-22759HIGHAuthenticated Remote Command Execution in ArubaOS Web-based Management InterfaceEPSS 1.6%CVE-2023-22761HIGHAuthenticated Remote Command Execution in ArubaOS Web-based Management InterfaceEPSS 1.6%CVE-2019-5405A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5EPSS 1.6%CVE-2024-31471CRITICALThere is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code eEPSS 1.6%CVE-2024-31472CRITICALThere are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code executioEPSS 1.6%CVE-2023-35972HIGHAuthenticated Remote Command Execution in ArubaOS Web-based Management InterfaceEPSS 1.6%CVE-2019-5408Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systeEPSS 1.6%CVE-2024-54007HIGHAuthenticated Remote Command Injection Vulnerability in the Web Interface of a 501 Wireless Client BridgeEPSS 1.6%CVE-2024-54006HIGHAuthenticated Remote Command Injection Vulnerability in the Web Interface of a 501 Wireless Client BridgeEPSS 1.6%CVE-2024-11622HIGHAn XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainEPSS 1.5%CVE-2022-43541HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.5%CVE-2022-37924HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.5%CVE-2024-42503HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the Lua Package Within the AOS Command Line Interface (CLI)EPSS 1.5%CVE-2024-42505CRITICALUnauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI ProtocolEPSS 1.5%