VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2026-73762MedSep 1, 2026
    risk 0.43cvss 6.6epss 0.00

    A vulnerability has been identified in the API endpoint of AOS-CX that could allow a remote actor to circumvent existing access controls. In some cases this could enable unauthorized access to management functionality that should be restricted by the configured access control…

  • CVE-2025-23060MedFeb 4, 2025
    risk 0.43cvss 6.6epss 0.00

    A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to…

  • CVE-2023-39267MedAug 29, 2023
    risk 0.43cvss 6.6epss 0.01

    An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch.

  • CVE-2019-12000MedJul 17, 2020
    risk 0.43cvss 6.6epss 0.01

    HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the…

  • CVE-2018-7113MedDec 3, 2018
    risk 0.43cvss 6.6epss 0.01

    A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates.

  • CVE-2017-5798MedFeb 15, 2018
    risk 0.43cvss 6.1epss 0.10

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

  • CVE-2017-5795MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.02

    A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was found.

  • CVE-2017-12555MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.03

    A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.

  • CVE-2016-8521MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.03

    A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

  • CVE-2026-76699MedSep 15, 2026
    risk 0.42cvss 6.4epss 0.00

    A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to…

  • CVE-2026-76697MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be…

  • CVE-2026-76696MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and…

  • CVE-2026-76695MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker…

  • CVE-2026-73788MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially…

  • CVE-2026-73772MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of…

  • CVE-2026-73761MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated information disclosure by sending a specially crafted packet. Successful exploitation of this vulnerability results in the ability to disclose sensitive…

  • CVE-2026-73760MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated Path Traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to read arbitrary files from the web-based management interface of the underlying operating system, which could lead to remote unauthorized access to…

  • CVE-2026-73759MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets. Successful exploitation of these vulnerabilities results in disruption of normal operation on affected devices.

  • CVE-2026-73758MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2026-73757MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the AOS-CX host,…

  • CVE-2026-73730MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2026-73729MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to upstream AFC dependencies to view sensitive information. Successful exploitation could allow an attacker to access…

  • CVE-2026-73728MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Denial-of-service vulnerabilities exist in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected…

  • CVE-2026-73727MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to access sensitive information. A successful exploit allows an attacker to access data beyond what is authorized by the user's existing privilege level, which…

  • CVE-2026-63457MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

  • CVE-2026-23817MedMar 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.

  • CVE-2026-23598MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system…

  • CVE-2026-23597MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could allow an attacker to access details such as user accounts, roles, and system…

  • CVE-2026-23596MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.

  • CVE-2025-37177MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete…

  • CVE-2025-37176MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.01

    A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands…

  • CVE-2025-37162MedNov 18, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2025-37137MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37136MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37135MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…

  • CVE-2025-37130MedSep 16, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.

  • CVE-2025-27078MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.

  • CVE-2025-23054MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user…

  • CVE-2024-51772MedDec 3, 2024
    risk 0.42cvss 6.4epss 0.00

    An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2024-51766MedNov 22, 2024
    risk 0.42cvss 6.5epss 0.00

    A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series.

  • CVE-2024-22436MedMar 26, 2024
    risk 0.42cvss 6.5epss 0.00

    A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.

  • CVE-2021-41005MedApr 12, 2022
    risk 0.42cvss 6.5epss 0.01

    A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

  • CVE-2021-26587MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.01

    A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the…

  • CVE-2021-26581MedApr 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is…

  • CVE-2020-7196MedOct 26, 2020
    risk 0.42cvss 6.5epss 0.01

    The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the…

  • CVE-2020-24623MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.01

    A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API Framework for VMware Esxi v2.5.2 and HPE Universal API Framework for Microsoft…

  • CVE-2020-7134MedApr 24, 2020
    risk 0.42cvss 6.5epss 0.01

    A remote access to sensitive data vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.

  • CVE-2019-12001MedApr 17, 2020
    risk 0.42cvss 6.4epss 0.01

    A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and…

  • CVE-2019-5408MedAug 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hosts and storage systems that are managed by Device Manager server. This problem is due to a vulnerability in Device Manager GUI. The following products are…

  • CVE-2019-11946MedJun 5, 2019
    risk 0.42cvss 6.5epss 0.01

    A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Page 16 of 22