Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2019-5398—A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 0.7%CVE-2023-22776MEDIUMAuthenticated Remote Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File ReadEPSS 0.7%CVE-2024-33519HIGHAuthenticated Server-Side prototype pollution Leading to Information DisclosureEPSS 0.7%CVE-2026-73720HIGHAuthenticated Insecure File Handling allows Remote Code Execution in HPE Networking Fabric Composer APIEPSS 0.7%CVE-2023-45617HIGHThere are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). SuccessfulEPSS 0.7%CVE-2023-45618HIGHThere are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol).EPSS 0.7%CVE-2023-45619HIGHThere is an arbitrary file deletion vulnerability in the RSSI service accessed by PAPI (Aruba's access point management protocol). SuccessfuEPSS 0.7%CVE-2026-73717HIGHUnauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.7%CVE-2024-41134HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.7%CVE-2026-23593HIGHUnauthenticated Limited File Read allows Data Exposure in Web InterfaceEPSS 0.7%CVE-2026-76685HIGHUnauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.7%CVE-2025-37138MEDIUMAuthenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)EPSS 0.7%CVE-2025-37158MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-37157MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-37184CRITICALUnauthenticated Bypass Allows Multi-Factor Authentication CircumventionEPSS 0.7%CVE-2026-73765HIGHAuthenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CXEPSS 0.7%CVE-2026-76709CRITICALUnauthenticated Remote Arbitrary File Write Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.7%CVE-2026-76708CRITICALUnauthenticated Remote Unauthorized Access Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.7%CVE-2023-30508MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%CVE-2023-30509MEDIUMAuthenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line InterfaceEPSS 0.6%