VYPR

Vendor CVEs

HPE

All CVEs

938 total · sorted by risk
  • CVE-2025-37126HigSep 16, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2025-37107HigJul 16, 2025
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2025-37106HigJul 16, 2025
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2025-37102HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system…

  • CVE-2025-37091HigJun 2, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-23052HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2025-23051HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.

  • CVE-2024-54007HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.02

    Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…

  • CVE-2024-54006HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.02

    Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…

  • CVE-2024-54008HigDec 10, 2024
    risk 0.47cvss 7.2epss 0.01

    An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.

  • CVE-2024-51771HigDec 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the…

  • CVE-2024-47463HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on…

  • CVE-2024-47462HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on…

  • CVE-2024-47461HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.02

    An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This…

  • CVE-2024-41915HigJul 30, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify…

  • CVE-2024-41135HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41134HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41133HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-33519HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to…

  • CVE-2024-22443HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary…

  • CVE-2024-31476HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2024-22437HigApr 15, 2024
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

  • CVE-2023-50271HigDec 17, 2023
    risk 0.47cvss 7.2epss 0.01

    A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.

  • CVE-2023-30912HigOct 25, 2023
    risk 0.47cvss 7.2epss 0.01

    A remote code execution issue exists in HPE OneView.

  • CVE-2023-1168HigMar 22, 2023
    risk 0.47cvss 7.2epss 0.01

    An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to…

  • CVE-2022-37933HigJan 5, 2023
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome…

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2022-28633HigAug 12, 2022
    risk 0.47cvss 7.3epss 0.00

    A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to read and write to the…

  • CVE-2022-28630HigAug 12, 2022
    risk 0.47cvss 7.3epss 0.00

    A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to execute arbitrary code resulting in a complete loss of confidentiality and…

  • CVE-2021-29220HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.02

    Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and…

  • CVE-2021-29214HigDec 10, 2021
    risk 0.47cvss 7.2epss 0.01

    A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays…

  • CVE-2019-5406HigAug 9, 2019
    risk 0.47cvss 7.2epss 0.01

    A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2018-7105HigSep 27, 2018
    risk 0.47cvss 7.2epss 0.04

    A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to…

  • CVE-2018-7078HigAug 6, 2018
    risk 0.47cvss 7.2epss 0.07

    A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

  • CVE-2025-37147HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or…

  • CVE-2025-37104HigJul 16, 2025
    risk 0.46cvss 7.1epss 0.00

    A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized…

  • CVE-2023-38402HigAug 15, 2023
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting…

  • CVE-2023-28089HigApr 25, 2023
    risk 0.46cvss 7.1epss 0.00

    An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

  • CVE-2019-11983HigJun 5, 2019
    risk 0.46cvss 7.0epss 0.01

    A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

  • CVE-2018-7119HigMay 10, 2019
    risk 0.46cvss 7.0epss 0.00

    A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series.…

  • CVE-2016-2015HigMay 14, 2016
    risk 0.46cvss 7.1epss 0.00

    HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2024-22439MedApr 15, 2024
    risk 0.45cvss 6.9epss 0.00

    A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to gain privileged access to switches resulting in information disclosure.

  • CVE-2019-11999MedApr 16, 2020
    risk 0.45cvss 6.9epss 0.01

    Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross site scripting. HPE has made the following updates available to resolve the vulnerability in the impacted versions of OCMP. * For…

  • CVE-2025-37158MedNov 18, 2025
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

  • CVE-2025-37157MedNov 18, 2025
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

  • CVE-2025-37156MedNov 18, 2025
    risk 0.44cvss 6.8epss 0.00

    A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.

  • CVE-2025-37129MedSep 16, 2025
    risk 0.44cvss 6.7epss 0.00

    A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if…

  • CVE-2025-37128MedSep 16, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an…

  • CVE-2025-37088MedApr 22, 2025
    risk 0.44cvss 6.8epss 0.00

    A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on race conditions and configuration, this vulnerability may lead to local/cluster unauthorized access.

  • CVE-2025-27081MedApr 10, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service.

Page 13 of 19