Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-25595MEDIUMSensitive Information Disclosure in ClearPass OnGuard Ubuntu AgentEPSS 0.2%CVE-2025-37088MEDIUMA security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, EPSS 0.2%CVE-2026-76699MEDIUMUnauthenticated Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 0.2%CVE-2026-73735MEDIUMAuthenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer APIEPSS 0.2%CVE-2023-30904—A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.EPSS 0.2%CVE-2023-30906HIGHThe vulnerability could be locally exploited to allow escalation of privilege. EPSS 0.2%CVE-2026-23811MEDIUMUnauthorized Bi-Directional Traffic Interception via L2/L3 ManipulationEPSS 0.2%CVE-2025-37147HIGHSecure Boot Bypass allows for Compromise of Hardware Root of TrustEPSS 0.2%CVE-2026-73742MEDIUMImproper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API EndpointEPSS 0.2%CVE-2026-73770HIGHAuthenticated Arbitrary File Write Vulnerability Leading to Remote Code Execution in AOS-CXEPSS 0.1%CVE-2026-23599HIGHLocal Privilege Escalation Vulnerability in HPE Aruba Networking Clear Pass Policy Manager OnGuard for LinuxEPSS 0.1%CVE-2022-37929MEDIUMImproper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary FlEPSS 0.1%CVE-2026-23812MEDIUMSecurity Boundary Bypass via Routing Node ImpersonationEPSS 0.1%CVE-2026-73743LOWUnauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric ComposerEPSS 0.1%CVE-2025-37149MEDIUMA potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.EPSS 0.1%CVE-2026-73737MEDIUMUnauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File ModificationEPSS 0.1%CVE-2025-37139MEDIUMVulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable BootEPSS 0.1%CVE-2024-51764MEDIUMA security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerabiEPSS 0.1%CVE-2024-51765MEDIUMA security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability mEPSS 0.1%CVE-2026-44873MEDIUMInsufficient Session Invalidation on User Account Deactivation in AOS-8 Operating SystemEPSS 0.1%