Vulnerabilidades em Hewlett Packard Enterprise (HPE)

459 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2025-37164CRITICALA remote code execution issue exists in HPE OneView.EPSS 90.0%KEVCVE-2024-53675HIGHAn XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainEPSS 83.9%CVE-2024-53676CRITICALA directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.EPSS 51.3%CVE-2024-53674HIGHAn XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainEPSS 47.4%CVE-2024-26304CRITICALThere is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code executionEPSS 44.0%CVE-2024-26305CRITICALThere is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sendinEPSS 15.2%CVE-2024-33512CRITICALThere is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remEPSS 14.6%CVE-2024-33511CRITICALThere is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code executEPSS 14.6%CVE-2019-5396A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 5.1%CVE-2019-5402A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5EPSS 4.3%CVE-2019-5397A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 4.3%CVE-2022-37932HIGHA potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. TEPSS 2.6%CVE-2019-5399A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 2.4%CVE-2019-5395A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 2.3%CVE-2023-45616CRITICALThere is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution bEPSS 2.1%CVE-2023-45614CRITICALThere are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending EPSS 2.1%CVE-2023-45615CRITICALThere are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending EPSS 2.1%CVE-2023-22779CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22786CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22785CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%