Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-37438MEDIUMAuthenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management InterfaceEPSS 0.8%CVE-2023-37436MEDIUMAuthenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management InterfaceEPSS 0.8%CVE-2023-37435MEDIUMAuthenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management InterfaceEPSS 0.8%CVE-2023-22773HIGHAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.EPSS 0.8%CVE-2023-22774HIGHAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.EPSS 0.8%CVE-2024-51771HIGHAuthenticated Remote Code Execution (RCE) via OGNL Injection in HPE Aruba Networking ClearPass Web-Based Management InterfaceEPSS 0.8%CVE-2026-76691HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API EndpointEPSS 0.8%CVE-2024-41135HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.8%CVE-2024-41133HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.8%CVE-2026-44880HIGHLow-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%CVE-2023-22772MEDIUMAuthenticated Path Traversal in ArubaOS Web-based Management Interface Allows for Arbitrary File DeletionEPSS 0.7%CVE-2026-23813CRITICALAuthentication Bypass in Web Interface allows Unauthenticated Admin Password ResetEPSS 0.7%CVE-2025-23058HIGHAuthenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.7%CVE-2022-43518MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnEPSS 0.7%CVE-2022-44532MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of EPSS 0.7%CVE-2024-53673HIGHA java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.EPSS 0.7%CVE-2023-35975MEDIUMAuthenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File DeletionEPSS 0.7%CVE-2022-37919HIGHA vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based EPSS 0.7%CVE-2025-23051HIGHAuthenticated Remote Code Execution in AOS Web-based Management InterfaceEPSS 0.7%CVE-2022-37937CRITICALPre-auth memory corruption in HPE ServiceguardEPSS 0.7%