Vulnerabilidades em Hewlett Packard Enterprise

313 resultados
Análise Vexday

O portfólio de vulnerabilidades catalogadas da Hewlett Packard Enterprise soma 311 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere menor pressão imediata de ameaças em curso. Ainda assim, a presença de 13 CVEs com prova de conceito pública e 3 de severidade crítica mantém a superfície de ataque relevante para equipes de gestão de risco. O destaque de atenção é CVE-2017-12542, com score EPSS de 0,9934, indicando probabilidade muito elevada de exploração, e associada ao tipo de falha mais recorrente no portfólio, CWE-78 (OS Command Injection), padrão que historicamente viabiliza execução remota de comandos com alto impacto. A ausência de novas CVEs nos últimos 90 dias reduz a pressão de remediação imediata, mas a antiguidade de vulnerabilidades de alto EPSS ainda ativas reforça a necessidade de revisão do inventário de ativos expostos.

CVE-2016-4404A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited rEPSS 14.8%CVE-2017-12500A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was reEPSS 14.7%CVE-2017-8982A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.EPSS 14.2%CVE-2016-4403A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited rEPSS 13.6%CVE-2018-7115HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001EPSS 13.4%CVE-2016-8527Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is pEPSS 13.2%CVE-2018-7076A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04.EPSS 12.3%CVE-2017-5822A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 11.9%CVE-2017-8955A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.EPSS 11.8%CVE-2017-5818A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 11.8%CVE-2017-8984A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.EPSS 11.1%CVE-2017-8958A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 and earlier was found.EPSS 11.1%CVE-2017-8946A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.EPSS 10.7%CVE-2018-7116HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote denial of service via dbman Opcode 10003 EPSS 10.3%CVE-2017-8956A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 10.2%CVE-2016-8526Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML pEPSS 9.8%CVE-2016-8525A Remote Disclosure of Information vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMEPSS 9.0%CVE-2018-7103A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier tEPSS 8.9%CVE-2018-7104A Remote Code Execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Services Manager Software earlier tEPSS 8.9%CVE-2017-8981A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.EPSS 8.7%