Vulnerabilidades en Hewlett Packard Enterprise (HPE)

598 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-73754MEDIUMAuthenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CXEPSS 0.3%CVE-2024-5486MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.3%CVE-2023-25596MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.3%CVE-2026-73709HIGHUnauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation ProcessEPSS 0.3%CVE-2022-37940MEDIUMPotential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exEPSS 0.3%CVE-2026-23825HIGHUnauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling ComponentEPSS 0.3%CVE-2026-23824HIGHUnauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling ComponentEPSS 0.3%CVE-2026-73731MEDIUMUnauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.3%CVE-2026-76704MEDIUMAuthenticated Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.3%CVE-2024-25616LOWAruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiatEPSS 0.3%CVE-2025-37131MEDIUMAuthenticated Arbitrary File Read allows Data Exposure in CLI InterfaceEPSS 0.3%CVE-2026-73734MEDIUMUnauthenticated Open Redirect allows URL Manipulation in HPE Networking Fabric Composer Web InterfaceEPSS 0.3%CVE-2026-23818HIGHOpen Redirect Vulnerability in HPE Aruba Networking Private 5G Core On-PremEPSS 0.3%CVE-2025-37130MEDIUMUnrestricted Binary allows File Enumeration in Underlying Operating SystemEPSS 0.3%CVE-2026-73714HIGHAuthenticated Sensitive Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2025-37128MEDIUMAuthenticated Arbitrary Process Termination allows potential System Disruption in ECOSEPSS 0.3%CVE-2026-23595HIGHUnauthenticated Authentication Bypass in application API allows unauthorized administrative account creationEPSS 0.3%CVE-2026-73764HIGHAuthentication Bypass Vulnerabilities Leading to Unauthorized Modification and Service Disruption in AOS-CXEPSS 0.3%CVE-2026-73755MEDIUMPrivilege Escalation via Unauthorized Access to Sensitive Session InformationEPSS 0.3%CVE-2026-73757MEDIUMAuthenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CXEPSS 0.3%