Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.0%CVE-2026-73767HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 1.0%CVE-2023-37434MEDIUMAuthenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management InterfaceEPSS 1.0%CVE-2026-44854HIGHAuthenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management InterfaceEPSS 1.0%CVE-2026-44853HIGHAuthenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management InterfaceEPSS 1.0%CVE-2025-37163HIGHAuthenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLIEPSS 1.0%CVE-2019-5407A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3EPSS 1.0%CVE-2023-25589CRITICALUnauthenticated Arbitrary User Creation Leads to Complete System CompromiseEPSS 1.0%CVE-2026-23600CRITICALA remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).EPSS 1.0%CVE-2026-73722HIGHAuthenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management InterfaceEPSS 1.0%CVE-2026-23823HIGHAuthenticated Command Injection leads to RCE in AOS-10 CLI CommandEPSS 1.0%CVE-2022-43530HIGHVulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQEPSS 1.0%CVE-2022-43523HIGHMultiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remEPSS 1.0%CVE-2022-43521HIGHMultiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remEPSS 1.0%CVE-2022-43522HIGHMultiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remEPSS 1.0%CVE-2022-43519HIGHMultiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remEPSS 1.0%CVE-2022-43520HIGHMultiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remEPSS 1.0%CVE-2023-45626MEDIUMAn authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary codeEPSS 0.9%CVE-2026-23815HIGHAuthenticated Command Injection found in AOS-CX Administrative CLI CommandEPSS 0.9%CVE-2024-26295HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%