Vulnerabilidades em Hewlett Packard Enterprise (HPE)

598 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2024-26294HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26296HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26297HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26298HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-44865HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 0.9%CVE-2024-41136MEDIUMAuthenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.9%CVE-2022-44535HIGHA vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote low-privileged authenticated uEPSS 0.9%CVE-2026-44867HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 0.9%CVE-2026-44866HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 0.9%CVE-2026-44868HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 0.9%CVE-2026-44869HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 0.9%CVE-2026-44870HIGHAuthenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating SystemsEPSS 0.9%CVE-2025-37146HIGHUnauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code ExecutionEPSS 0.9%CVE-2025-37162MEDIUMAuthenticated Command Injection Vulnerability Leading to Arbitrary Remote Command ExecutionEPSS 0.9%CVE-2019-5400A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.EPSS 0.9%CVE-2024-47464MEDIUMAuthenticated Path Traversal Vulnerability Leads to a Remote Unauthorized Access to FilesEPSS 0.9%CVE-2023-45620HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.9%CVE-2023-45623HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Wi-Fi Uplink service accessed via the PAPI protocol. Successful exploitEPSS 0.9%CVE-2023-45621HIGHUnauthenticated Denial-of-Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.9%CVE-2023-45624HIGHAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the soft ap daemon accessed via the PAPI protocol. Successful exploitatioEPSS 0.9%