Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2025-37144MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2025-37145MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2024-31474HIGHThere is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). SuccessfulEPSS 0.4%CVE-2024-31475HIGHThere is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management prEPSS 0.4%CVE-2025-37168HIGHUnauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating SystemEPSS 0.4%CVE-2026-76673CRITICALAuthentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2025-27078MEDIUMAuthenticated Remote Command Execution caused by Insecure Function Usage in System BinaryEPSS 0.4%CVE-2023-22771MEDIUMInsufficient Session Expiration in ArubaOS Command Line InterfaceEPSS 0.4%CVE-2026-44852HIGHAuthenticated Remote Code Execution via Arbitrary File Overwrite in the AOS-8 and AOS-10 Web-Based Management InterfaceEPSS 0.4%CVE-2026-76658CRITICALUnauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH DaemonEPSS 0.4%CVE-2026-73760MEDIUMAuthenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CXEPSS 0.4%CVE-2026-76712HIGHUnauthenticated Remote Unauthorized Access, Information Disclosure, and Denial of Service Vulnerabilities in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2023-38484HIGHMultiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and GatewaysEPSS 0.4%CVE-2026-63456CRITICALAuthentication bypass via spoofed HTTP headers Orchestrator REST APIEPSS 0.4%CVE-2026-76657CRITICALAuthentication Bypass in HPE Networking Fabric Composer API allows Administrative AccessEPSS 0.4%CVE-2025-37173HIGHImproper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)EPSS 0.4%CVE-2022-43529MEDIUMA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persistEPSS 0.4%CVE-2024-22436MEDIUMA security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.EPSS 0.4%CVE-2024-6206HIGHA security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerabiliEPSS 0.4%CVE-2022-43532HIGH A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct aEPSS 0.4%