Vulnerabilidades em Hewlett Packard Enterprise (HPE)

588 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2022-37939LOWA potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locaEPSS 0.2%CVE-2025-27087MEDIUMA vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.EPSS 0.2%CVE-2026-73745LOWUnauthenticated Limited Information Disclosure allows Data Exposure in the API of HPE Networking Fabric ComposerEPSS 0.2%CVE-2024-54009MEDIUMRemote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited EPSS 0.2%CVE-2026-73718HIGHUnauthenticated Information Disclosure in Web Interface allows Sensitive Data Exposure in HPE Networking Fabric ComposerEPSS 0.2%CVE-2026-73746LOWAuthenticated Denial of Service Vulnerability in HPE Networking Fabric Composer APIEPSS 0.2%CVE-2023-28085MEDIUMAn HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentialsEPSS 0.2%CVE-2026-23810MEDIUMCross-BSSID GTK Re-encryption and Traffic InjectionEPSS 0.2%CVE-2026-73772MEDIUMUnauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CXEPSS 0.2%CVE-2022-43535HIGHA vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. AEPSS 0.2%CVE-2026-73733MEDIUMAuthentication Bypasses in API allow Continued Authenticated Access in HPE Networking Fabric ComposerEPSS 0.2%CVE-2023-25590HIGHLocal Privilege Escalation in ClearPass OnGuard Linux AgentEPSS 0.2%CVE-2023-30903—HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6. EPSS 0.2%CVE-2022-43540MEDIUMA vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtaEPSS 0.2%CVE-2026-73730MEDIUMAuthenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Composer APIEPSS 0.2%CVE-2023-28088HIGHAn HPE OneView appliance dump may expose SAN switch administrative credentialsEPSS 0.2%CVE-2025-37186HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for LinuxEPSS 0.2%CVE-2026-73779HIGHAuthentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CXEPSS 0.2%CVE-2023-28090MEDIUMAn HPE OneView appliance dump may expose SNMPv3 read credentialsEPSS 0.2%CVE-2023-28087MEDIUMAn HPE OneView appliance dump may expose OneView user accountsEPSS 0.2%