Vulnerabilidades em Hewlett Packard Enterprise

313 resultados
Análise Vexday

O portfólio de vulnerabilidades catalogadas da Hewlett Packard Enterprise soma 311 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere menor pressão imediata de ameaças em curso. Ainda assim, a presença de 13 CVEs com prova de conceito pública e 3 de severidade crítica mantém a superfície de ataque relevante para equipes de gestão de risco. O destaque de atenção é CVE-2017-12542, com score EPSS de 0,9934, indicando probabilidade muito elevada de exploração, e associada ao tipo de falha mais recorrente no portfólio, CWE-78 (OS Command Injection), padrão que historicamente viabiliza execução remota de comandos com alto impacto. A ausência de novas CVEs nos últimos 90 dias reduz a pressão de remediação imediata, mas a antiguidade de vulnerabilidades de alto EPSS ainda ativas reforça a necessidade de revisão do inventário de ativos expostos.

CVE-2017-8988A Remote Bypass of Security Restrictions vulnerability was identified in HPE XP Command View Advanced Edition Software Earlier than 8.5.3-00EPSS 2.7%CVE-2017-8966A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.6%CVE-2017-8962A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.6%CVE-2017-8992HPE has identified a remote privilege escalation vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This isEPSS 2.6%CVE-2016-4406A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44EPSS 2.6%CVE-2017-12560A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.EPSS 2.5%CVE-2017-12559A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.EPSS 2.5%CVE-2018-7108HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vuEPSS 2.5%CVE-2018-7077A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), ConfigEPSS 2.4%CVE-2017-5787A remote denial of service vulnerability in HPE Version Control Repository Manager (VCRM) in all versions prior to 7.6 was found.EPSS 2.3%CVE-2017-8960An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found.EPSS 2.3%CVE-2017-5802A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found.EPSS 2.3%CVE-2018-7095A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be exploited remEPSS 2.2%CVE-2017-5796A Remote Cross Site Request Forgery (CSRF) vulnerability in HPE 2620 Series Network Switches version RA.15.05.0006 was found.EPSS 2.1%CVE-2017-8967A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.1%CVE-2017-8964A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.1%CVE-2017-8965A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.1%CVE-2017-8963A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2EPSS 2.1%CVE-2016-8515A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prEPSS 1.9%CVE-2018-7070HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. ThEPSS 1.9%