Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-35977MEDIUMAuthenticated Sensitive Information Disclosure in ArubaOS Command Line InterfaceEPSS 0.5%CVE-2023-35976MEDIUMAuthenticated Sensitive Information Disclosure in ArubaOS Command Line InterfaceEPSS 0.5%CVE-2024-31482MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful eEPSS 0.5%CVE-2025-27082HIGHAuthenticated Remote Code Execution Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File WriteEPSS 0.5%CVE-2025-37132HIGHAuthenticated Remote Code Execution Vulnerability in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File WriteEPSS 0.5%CVE-2019-5403—A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): priEPSS 0.5%CVE-2024-41915HIGHAuthenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management InterfaceEPSS 0.5%CVE-2026-63454HIGHAuthenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CXEPSS 0.5%CVE-2026-76705MEDIUMAuthenticated Buffer Overflow Vulnerability in an API Endpoint Leads to Remote Code Execution in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-76710HIGHUnauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.5%CVE-2026-23827HIGHUnauthenticated Remote Code Execution via Heap Buffer Overflow in Network Management ServiceEPSS 0.5%CVE-2023-37423HIGHAuthenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration InterfaceEPSS 0.5%CVE-2023-37422HIGHAuthenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration InterfaceEPSS 0.5%CVE-2023-37421HIGHAuthenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration InterfaceEPSS 0.5%CVE-2024-33518MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. SucceEPSS 0.5%CVE-2026-73701CRITICALUnauthenticated Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.5%CVE-2024-26303MEDIUMAuthenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon EPSS 0.5%CVE-2026-76682HIGHUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2024-26301MEDIUMA vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low priviEPSS 0.5%CVE-2024-25614MEDIUMThere is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the aEPSS 0.5%