Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2022-37927MEDIUMURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). EPSS 0.4%CVE-2023-43508MEDIUMAuthorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.4%CVE-2025-37178MEDIUMOut-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemEPSS 0.4%CVE-2024-24456MEDIUMAn E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentially due to a buffer EPSS 0.4%CVE-2024-24452MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attacEPSS 0.4%CVE-2025-23054MEDIUMAuthenticated Response Manipulation allows Unauthorized Actions in Management InterfaceEPSS 0.4%CVE-2025-23053MEDIUMAuthenticated privilege escalation via broken access controlEPSS 0.4%CVE-2026-73723HIGHAuthenticated Privilege Escalation Leading to Unauthorized State Changes in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.4%CVE-2022-43528MEDIUMUnder certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authenticaEPSS 0.4%CVE-2025-37135MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2025-37136MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2025-37137MEDIUMAuthenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)EPSS 0.4%CVE-2026-73788MEDIUMPrivilege Escalation in ClearPass OnGuard AgentEPSS 0.4%CVE-2024-41916MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.4%CVE-2025-37177MEDIUMAuthenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)EPSS 0.4%CVE-2024-24457MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allowsEPSS 0.4%CVE-2024-24454MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackersEPSS 0.4%CVE-2024-24459MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cEPSS 0.4%CVE-2024-24455MEDIUMAn invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows aEPSS 0.4%CVE-2026-76680HIGHAuthenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosure in EdgeConnect SD-WAN OrchestratorEPSS 0.4%