Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-30912HIGH A remote code execution issue exists in HPE OneView. EPSS 1.2%CVE-2024-25611HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.2%CVE-2024-25612HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.2%CVE-2024-25613HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.2%CVE-2024-1356HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.2%CVE-2025-23052HIGHAuthenticated Command Injection Vulnerability allows Unauthorized Command Execution in CLI InterfaceEPSS 1.2%CVE-2026-44871HIGHAuthenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating SystemsEPSS 1.2%CVE-2025-37134HIGHAuthenticated Command Injection Vulnerability in the Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 1.2%CVE-2025-37133HIGHAuthenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage.EPSS 1.2%CVE-2022-43542HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.2%CVE-2025-37091HIGHA command injection remote code execution vulnerability exists in HPE StoreOnce Software.EPSS 1.2%CVE-2024-31470CRITICALThere is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthentiEPSS 1.2%CVE-2025-37095MEDIUMA directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.EPSS 1.2%CVE-2025-27083HIGHAuthenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceEPSS 1.2%CVE-2024-42501HIGHAuthenticated Path Traversal Vulnerability Leads to a Remote Command Execution (RCE)EPSS 1.2%CVE-2024-47463HIGHArbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Command Execution (RCE)EPSS 1.2%CVE-2024-47462HIGHArbitrary File Creation Vulnerability in Instant AOS-8 and AOS-10 leads to Authenticated Remote Command Execution (RCE)EPSS 1.2%CVE-2023-1168HIGHAuthenticated Remote Code Execution in Aruba CX SwitchesEPSS 1.1%CVE-2024-31468CRITICALThere are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code exEPSS 1.1%CVE-2024-31466CRITICALUnauthenticated Buffer Overflow Vulnerabilities in CLI Service Accessed by the PAPI ProtocolEPSS 1.1%