Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-76706MEDIUMUnauthenticated Information Disclosure in EdgeConnect SD-WAN Orchestrator API allows exposure of sensitive dataEPSS 0.4%CVE-2026-76717MEDIUMUnauthenticated Remote Sensitive Information Disclosure Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.4%CVE-2026-76694MEDIUMAuthenticated Privilege Escalation Vulnerability in the Command Line Interface of HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2025-37087CRITICALA vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary filEPSS 0.4%CVE-2024-42500CRITICALHPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.EPSS 0.4%CVE-2024-31483MEDIUMAn authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitEPSS 0.4%CVE-2024-53672MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.4%CVE-2023-38485HIGHMultiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and GatewaysEPSS 0.4%CVE-2026-73715HIGHUnauthenticated Denial-of-Service (DoS) Vulnerability in the API of HPE Networking Fabric ComposerEPSS 0.4%CVE-2026-23826HIGHUnauthenticated Denial of Service in AOS-8 Network Management ServiceEPSS 0.4%CVE-2026-73712HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric Composer APIEPSS 0.4%CVE-2025-37124HIGHUnauthenticated Access Vulnerability allows Transit Traffic Misrouting in SD-WAN Edge InterfaceEPSS 0.4%CVE-2025-37165HIGHExposure of VLAN information in unintended network interfacesEPSS 0.4%CVE-2026-76672CRITICALAuthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2026-76701MEDIUMUnauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2024-42395CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the AP Certificate Management Service Accessed by the PAPI ProtocolEPSS 0.4%CVE-2026-76669CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2026-76670CRITICALAuthorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN OrchestratorEPSS 0.4%CVE-2025-37161HIGHUnauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management InterfaceEPSS 0.4%CVE-2025-37143MEDIUMAuthenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required)EPSS 0.4%