Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2024-24453MEDIUMAn invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME EPSS 0.4%CVE-2024-24458MEDIUMAn invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.EPSS 0.4%CVE-2024-26300MEDIUMA vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-siEPSS 0.4%CVE-2024-26299MEDIUMA vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a EPSS 0.4%CVE-2025-37125HIGHBroken access control vulnerability in Firewall Configuration Leads to Unauthorized Access to Internal Network ResourcesEPSS 0.4%CVE-2026-76693HIGHUnauthenticated Denial-of-Service Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.4%CVE-2025-37179MEDIUMOut-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemEPSS 0.4%CVE-2024-26302MEDIUMA vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low priviEPSS 0.4%CVE-2026-76681HIGHAuthenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Orchestrator APIEPSS 0.4%CVE-2025-37142MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2025-37140MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2025-37141MEDIUMAuthenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 0.4%CVE-2026-76676HIGHUnauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in EdgeConnect SD-WAN GatewaysEPSS 0.3%CVE-2026-23598MEDIUMUnauthenticated Information Disclosure in application API allows sensitive system information exposureEPSS 0.3%CVE-2025-25042MEDIUMAuthenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST InterfaceEPSS 0.3%CVE-2026-73727MEDIUMAuthenticated Sensitive Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-73703HIGHUnauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 0.3%CVE-2026-73707HIGHAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer APIEPSS 0.3%CVE-2026-73724HIGHAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric ComposerEPSS 0.3%CVE-2023-38486HIGHHardware Root of Trust Bypass in 9200 and 9000 Series Controllers and GatewaysEPSS 0.3%