Vulnerabilidades en Hewlett Packard Enterprise (HPE)

598 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2022-37933HIGHA potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be explEPSS 0.3%CVE-2022-43539MEDIUM A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position tEPSS 0.3%CVE-2026-23819HIGHError in SSID Processing allows Stored XSS in Web Management InterfaceEPSS 0.3%CVE-2026-73741MEDIUMAuthenticated Limited File Read allows Data Exposure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-63457MEDIUMA potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.EPSS 0.3%CVE-2026-76696MEDIUMUnauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2025-23055MEDIUMAuthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Aruba Networking Fabric Composer Web Management InterfaceEPSS 0.3%CVE-2025-23057MEDIUMAuthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Aruba Networking Fabric Composer Web Management InterfaceEPSS 0.3%CVE-2025-23056MEDIUMAuthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Aruba Networking Fabric Composer Web Management InterfaceEPSS 0.3%CVE-2025-37185MEDIUMAuthenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration InterfaceEPSS 0.3%CVE-2026-23808MEDIUMClient Isolation Bypass via GTK ManipulationEPSS 0.3%CVE-2026-23822MEDIUMUnauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of ServiceEPSS 0.3%CVE-2026-73756MEDIUMUnauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API EndpointEPSS 0.3%CVE-2026-23809MEDIUMMAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic RedirectionEPSS 0.3%CVE-2026-76715HIGHUnauthenticated Man-in-the-Middle Attach Leads to Remote Code Execution Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.3%CVE-2026-23597MEDIUMUnauthenticated Information Disclosure in application API allows sensitive system information exposureEPSS 0.3%CVE-2025-37159MEDIUMAuthenticated Session Hijacking Allows Unauthorized Access in Network Switching SoftwareEPSS 0.3%CVE-2026-19766CRITICALAuthentication Bypass leads to Administrative control of adjacent network hosts in HPE Networking Fabric ComposerEPSS 0.3%CVE-2026-73735MEDIUMAuthenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-73726MEDIUMAuthentication Bypass in HPE Networking Fabric Composer allows Unauthorized Administrative AccessEPSS 0.3%