Vulnerabilidades em Hewlett Packard Enterprise (HPE)

459 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hewlett Packard Enterprise (HPE) soma 450 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — apenas 1 entrada confirmada no CISA KEV (0,22% contra 0,45% da média). Ainda assim, a CVE-2025-37164 merece atenção imediata: com EPSS de 0,8973, ela concentra a maior probabilidade de exploração observada no portfólio e é a vulnerabilidade ativamente explorada hoje. O tipo de falha mais recorrente é CWE-77 (Command Injection), o que sugere riscos elevados de execução arbitrária de comandos em ambientes afetados. Com 57 CVEs críticas, 3 com prova de conceito pública e 33 vulnerabilidades surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patch ativos e priorizar os ativos expostos a injeção de comandos.

CVE-2023-22783CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22782CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-35982CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22784CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22785CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-22780CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-35980CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2023-35981CRITICALUnauthenticated Buffer Overflow Vulnerabilities in Services Accessed by the PAPI ProtocolEPSS 2.1%CVE-2024-42509CRITICALUnauthenticated Command Injection Vulnerability in the CLI Service Accessed by the PAPI ProtocolEPSS 2.0%CVE-2023-45625HIGHMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilitiEPSS 1.8%CVE-2024-42502HIGHAuthenticated Remote Command Execution (RCE) Vulnerability in the AOS Command Line InterfaceEPSS 1.8%CVE-2022-37934MEDIUMA potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotelEPSS 1.8%CVE-2024-47461HIGHAuthenticated Arbitrary Remote Command Execution (RCE) in Instant AOS-8 and AOS-10EPSS 1.7%CVE-2023-22750CRITICALMultiple Unauthenticated Command Injections in the PAPI ProtocolEPSS 1.7%CVE-2023-22749CRITICALMultiple Unauthenticated Command Injections in the PAPI ProtocolEPSS 1.7%CVE-2023-22747CRITICALMultiple Unauthenticated Command Injections in the PAPI ProtocolEPSS 1.7%CVE-2023-22748CRITICALMultiple Unauthenticated Command Injections in the PAPI ProtocolEPSS 1.7%CVE-2023-22790HIGHAuthenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line InterfaceEPSS 1.7%CVE-2023-22788HIGHAuthenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line InterfaceEPSS 1.7%CVE-2023-22789HIGHAuthenticated Remote Command Execution in Aruba InstantOS or ArubaOS 10 Command Line InterfaceEPSS 1.7%