Vulnerabilidades en Hewlett Packard Enterprise (HPE)

450 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-44860HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.3%CVE-2026-44861HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.3%CVE-2026-44863HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.3%CVE-2026-44864HIGHAuthenticated Remote Code Execution via SQL Injection in AOS-8 and AOS-10 Operating SystemsEPSS 0.3%CVE-2025-25042MEDIUMAuthenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST InterfaceEPSS 0.3%CVE-2025-37177MEDIUMAuthenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)EPSS 0.3%CVE-2025-37179MEDIUMOut-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemEPSS 0.3%CVE-2026-44874MEDIUMAuthenticated Arbitrary File Download via AOS-10 Web-Based Management InterfaceEPSS 0.3%CVE-2025-37131MEDIUMAuthenticated Arbitrary File Read allows Data Exposure in CLI InterfaceEPSS 0.3%CVE-2026-23595HIGHUnauthenticated Authentication Bypass in application API allows unauthorized administrative account creationEPSS 0.3%CVE-2025-37130MEDIUMUnrestricted Binary allows File Enumeration in Underlying Operating SystemEPSS 0.3%CVE-2025-37128MEDIUMAuthenticated Arbitrary Process Termination allows potential System Disruption in ECOSEPSS 0.3%CVE-2023-38486HIGHHardware Root of Trust Bypass in 9200 and 9000 Series Controllers and GatewaysEPSS 0.3%CVE-2026-23817MEDIUMUnauthenticated Open Redirect allows URL Manipulation in Web InterfaceEPSS 0.3%CVE-2022-37928HIGHInsufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and NimbleEPSS 0.3%CVE-2024-42396MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.3%CVE-2024-42397MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerabilities in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.3%CVE-2022-37933HIGHA potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be explEPSS 0.3%CVE-2022-43539MEDIUM A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position tEPSS 0.3%CVE-2026-23819HIGHError in SSID Processing allows Stored XSS in Web Management InterfaceEPSS 0.3%