Vulnerabilidades em Hewlett Packard Enterprise

313 resultados
Análise Vexday

O portfólio de vulnerabilidades catalogadas da Hewlett Packard Enterprise soma 311 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere menor pressão imediata de ameaças em curso. Ainda assim, a presença de 13 CVEs com prova de conceito pública e 3 de severidade crítica mantém a superfície de ataque relevante para equipes de gestão de risco. O destaque de atenção é CVE-2017-12542, com score EPSS de 0,9934, indicando probabilidade muito elevada de exploração, e associada ao tipo de falha mais recorrente no portfólio, CWE-78 (OS Command Injection), padrão que historicamente viabiliza execução remota de comandos com alto impacto. A ausência de novas CVEs nos últimos 90 dias reduz a pressão de remediação imediata, mas a antiguidade de vulnerabilidades de alto EPSS ainda ativas reforça a necessidade de revisão do inventário de ativos expostos.

CVE-2017-8972A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.EPSS 0.7%CVE-2017-8971A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.EPSS 0.7%CVE-2018-7073A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.EPSS 0.7%CVE-2017-5781A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found.EPSS 0.7%CVE-2017-5827A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 0.7%CVE-2025-37099CRITICALA remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.EPSS 0.7%CVE-2018-7098A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploEPSS 0.7%CVE-2023-50274HIGHHPE OneView may allow command injection with local privilege escalation.EPSS 0.7%CVE-2016-8513A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versioEPSS 0.7%CVE-2018-7112The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information.EPSS 0.7%CVE-2017-8951A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.EPSS 0.7%CVE-2018-7110A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A rEPSS 0.7%CVE-2017-8950A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.EPSS 0.7%CVE-2017-8949A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.EPSS 0.6%CVE-2018-7080A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit EPSS 0.6%CVE-2025-37105HIGHAn hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.EPSS 0.6%CVE-2022-37910MEDIUMA buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denEPSS 0.6%CVE-2022-37907MEDIUMA vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an imEPSS 0.6%CVE-2016-8535A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found.EPSS 0.6%CVE-2017-5788A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI wasEPSS 0.6%