Vulnerabilidades em Hewlett Packard Enterprise (HPE)

450 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2022-43533HIGH A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A suEPSS 0.2%CVE-2025-23060MEDIUMSensitive Data Exposure Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM)EPSS 0.2%CVE-2023-38401HIGHLocal Privilege Escalation in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows ClientEPSS 0.2%CVE-2023-43506HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2025-27079MEDIUMArbitrary File Creation vulnerability allows for Authenticated Remote Code Execution in CLI InterfaceEPSS 0.2%CVE-2022-37935MEDIUMHPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.EPSS 0.2%CVE-2025-37129MEDIUMAuthenticated Remote Code Execution allows Exploit in Scripts FeatureEPSS 0.2%CVE-2023-38402HIGHArbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows ClientEPSS 0.2%CVE-2025-37104HIGHHPE Telco Service Orchestrator Software, Authenticated SQL InjectionEPSS 0.2%CVE-2023-28091MEDIUMHPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dumpEPSS 0.2%CVE-2022-37939LOWA potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locaEPSS 0.2%CVE-2025-27080MEDIUMAuthenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2025-37109LOWHPE Telco Service Activator, Protection Mechanism FailureEPSS 0.2%CVE-2025-37108LOWHPE Telco Service Activator, Protection Mechanism FailureEPSS 0.2%CVE-2024-54009MEDIUMRemote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited EPSS 0.2%CVE-2023-28085MEDIUMAn HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentialsEPSS 0.2%CVE-2026-23810MEDIUMCross-BSSID GTK Re-encryption and Traffic InjectionEPSS 0.2%CVE-2023-25590HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2022-43535HIGHA vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. AEPSS 0.2%CVE-2023-30903HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. EPSS 0.2%