Vulnerabilidades em Hewlett Packard Enterprise

311 resultados
Análise Vexday

O portfólio de vulnerabilidades catalogadas da Hewlett Packard Enterprise soma 311 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que sugere menor pressão imediata de ameaças em curso. Ainda assim, a presença de 13 CVEs com prova de conceito pública e 3 de severidade crítica mantém a superfície de ataque relevante para equipes de gestão de risco. O destaque de atenção é CVE-2017-12542, com score EPSS de 0,9934, indicando probabilidade muito elevada de exploração, e associada ao tipo de falha mais recorrente no portfólio, CWE-78 (OS Command Injection), padrão que historicamente viabiliza execução remota de comandos com alto impacto. A ausência de novas CVEs nos últimos 90 dias reduz a pressão de remediação imediata, mas a antiguidade de vulnerabilidades de alto EPSS ainda ativas reforça a necessidade de revisão do inventário de ativos expostos.

CVE-2016-4391A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.EPSS 20.4%CVE-2017-5824An unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 19.3%CVE-2017-8961A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.EPSS 19.1%CVE-2017-8976A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.EPSS 18.2%CVE-2017-8954A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.EPSS 18.2%CVE-2017-5823A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 18.2%CVE-2017-8957A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.EPSS 18.2%CVE-2017-5819A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 18.2%CVE-2017-5820A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 18.2%CVE-2017-8975A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.EPSS 18.2%CVE-2017-5790A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.EPSS 18.0%CVE-2017-5811A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.EPSS 17.0%CVE-2016-8523A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.EPSS 16.7%CVE-2017-8990A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) Wireless Service Manager (WSM) Software earlEPSS 16.7%CVE-2018-7074A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resEPSS 16.7%CVE-2017-5821A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.EPSS 16.5%CVE-2016-4402A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited rEPSS 16.4%CVE-2017-5808A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.EPSS 16.1%CVE-2016-8511A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.EPSS 15.3%CVE-2017-5799A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.EPSS 15.2%