Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2025-37182HIGHAuthenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.5%CVE-2024-25615MEDIUM An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. SuccEPSS 0.5%CVE-2026-76687HIGHAuthenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN OrchestratorEPSS 0.5%CVE-2026-76711HIGHUnauthenticated Remote Data Injection Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.5%CVE-2025-37166HIGHUnexpected shutdown in HPE Instant On Access Points after processing specific packetsEPSS 0.5%CVE-2023-35978MEDIUMReflected Cross-Site Scripting (XSS) in ArubaOS Web-based Management InterfaceEPSS 0.5%CVE-2026-73719HIGHAuthenticated Arbitrary File Write Vulnerability leads to Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.5%CVE-2022-43527MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2022-43526MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2022-43525MEDIUMMultiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attackeEPSS 0.5%CVE-2026-73750HIGHAuthenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code ExecutionEPSS 0.5%CVE-2026-44877MEDIUMUnauthenticated Remote Disclosure of Cryptographic SecretsEPSS 0.5%CVE-2024-51772MEDIUMAuthenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)EPSS 0.5%CVE-2023-25594MEDIUMAuthorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.5%CVE-2026-73716HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric ComposerEPSS 0.5%CVE-2025-37123HIGHAuthenticated Command Injection leads to Unauthorized Actions in CLI InterfaceEPSS 0.5%CVE-2026-76684HIGHAuthentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.5%CVE-2026-63455CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.5%CVE-2026-76700MEDIUMUnauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.5%CVE-2026-76697MEDIUMAuthenticated Information Disclosure in HPE Networking EdgeConnect Enterprise Web-Based Management InterfaceEPSS 0.5%