Vulnerabilidades em Hewlett Packard Enterprise

313 resultados
Análise Vexday

O portfólio de vulnerabilidades catalogadas da Hewlett Packard Enterprise soma 311 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere menor pressão imediata de ameaças em curso. Ainda assim, a presença de 13 CVEs com prova de conceito pública e 3 de severidade crítica mantém a superfície de ataque relevante para equipes de gestão de risco. O destaque de atenção é CVE-2017-12542, com score EPSS de 0,9934, indicando probabilidade muito elevada de exploração, e associada ao tipo de falha mais recorrente no portfólio, CWE-78 (OS Command Injection), padrão que historicamente viabiliza execução remota de comandos com alto impacto. A ausência de novas CVEs nos últimos 90 dias reduz a pressão de remediação imediata, mas a antiguidade de vulnerabilidades de alto EPSS ainda ativas reforça a necessidade de revisão do inventário de ativos expostos.

CVE-2024-22440MEDIUMHPE Compute Scale-up Server 3200 Server, Disclosure of Sensitive InformationEPSS 0.4%CVE-2017-8985HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability in HGLM version HGLM EPSS 0.4%CVE-2025-27086HIGHA vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.EPSS 0.4%CVE-2017-12552A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was foEPSS 0.4%CVE-2017-12548A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.4%CVE-2017-12547A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.4%CVE-2026-73785HIGHHPE IceWall Federation Agent and Proxy, Denial of Service vulnerabilityEPSS 0.4%CVE-2018-7099A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploEPSS 0.4%CVE-2024-51768HIGHAn hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 0.4%CVE-2018-7094A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locEPSS 0.4%CVE-2024-51769HIGHAn information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 0.4%CVE-2024-51770HIGHAn information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.EPSS 0.4%CVE-2017-12546A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.3%CVE-2017-12550A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.3%CVE-2017-12553A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.3%CVE-2017-12549A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.EPSS 0.3%CVE-2024-22444MEDIUMA vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflEPSS 0.3%CVE-2025-37101HIGHHPE OneView for VMware vCenter (OV4VC), Local Elevation of PrivilegeEPSS 0.3%CVE-2024-11856LOWHPE IceWall Products, Remote Unauthorized Data ModificationEPSS 0.3%CVE-2022-37909MEDIUMAruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The sceEPSS 0.3%