HPE Security Bulletin
by HPE
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-23595 | Hig | 0.57 | 8.8 | 0.00 | Feb 17, 2026 | An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access,… | ||
| CVE-2026-76685 | Hig | 0.53 | 8.1 | 0.01 | Sep 15, 2026 | A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer… | ||
| CVE-2024-42508 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2024 | This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users. | ||
| CVE-2025-37178 | Med | 0.34 | 5.3 | 0.00 | Jan 13, 2026 | Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific… | ||
| CVE-2025-37160 | Med | 0.34 | 5.3 | 0.00 | Nov 18, 2025 | A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data. |
- risk 0.57cvss 8.8epss 0.00
An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access,…
- risk 0.53cvss 8.1epss 0.01
A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer…
- risk 0.36cvss 5.5epss 0.00
This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
- risk 0.34cvss 5.3epss 0.00
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific…
- risk 0.34cvss 5.3epss 0.00
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.