VYPR

Vendor CVEs

HPE

All CVEs

938 total · sorted by risk
  • CVE-2025-37112MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2025-37111MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2025-37110MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2025-27080MedMar 18, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to…

  • CVE-2018-12181MedMar 27, 2019
    risk 0.39cvss 6.0epss 0.00

    Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.

  • CVE-2018-7108MedSep 27, 2018
    risk 0.39cvss 5.9epss 0.02

    HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific…

  • CVE-2016-9042MedJun 4, 2018
    risk 0.39cvss 5.9epss 0.04

    An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will…

  • CVE-2017-14360MedNov 8, 2017
    risk 0.39cvss 5.9epss 0.02

    A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).

  • CVE-2025-37159MedNov 18, 2025
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially…

  • CVE-2024-24455MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

  • CVE-2024-24453MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a…

  • CVE-2024-24452MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

  • CVE-2024-5486MedJul 30, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further…

  • CVE-2021-22267MedFeb 9, 2021
    risk 0.38cvss 5.9epss 0.01

    Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY,…

  • CVE-2019-11989MedJul 19, 2019
    risk 0.38cvss 5.9epss 0.02

    A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for…

  • CVE-2019-5392MedJun 5, 2019
    risk 0.38cvss 5.3epss 0.07

    A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7110MedOct 17, 2018
    risk 0.38cvss 5.9epss 0.01

    A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.

  • CVE-2016-1987MedFeb 18, 2016
    risk 0.38cvss 5.9epss 0.02

    HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

  • CVE-2025-37185MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2025-37094MedJun 2, 2025
    risk 0.36cvss 5.5epss 0.01

    A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-25041MedApr 1, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft…

  • CVE-2025-23057MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23056MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23055MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2024-51765MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

  • CVE-2024-51764MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

  • CVE-2024-42508MedOct 18, 2024
    risk 0.36cvss 5.5epss 0.00

    This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

  • CVE-2023-6573MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    HPE OneView may have a missing passphrase during restore.

  • CVE-2023-30904MedJun 16, 2023
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.

  • CVE-2023-30903MedJun 16, 2023
    risk 0.36cvss 5.5epss 0.00

    HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.

  • CVE-2023-28084MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

  • CVE-2023-28090MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose SNMPv3 read credentials

  • CVE-2023-28087MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose OneView user accounts

  • CVE-2023-28086MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose proxy credential settings

  • CVE-2023-28091MedApr 14, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump

  • CVE-2023-28085MedApr 14, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials

  • CVE-2022-37935MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.

  • CVE-2022-28625MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.00

    A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality,…

  • CVE-2022-23700MedApr 4, 2022
    risk 0.36cvss 5.5epss 0.00

    A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-26585MedJun 24, 2021
    risk 0.36cvss 5.5epss 0.00

    A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.

  • CVE-2021-26579MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM).…

  • CVE-2019-11998MedJan 16, 2020
    risk 0.36cvss 5.5epss 0.01

    HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information…

  • CVE-2018-7115MedDec 3, 2018
    risk 0.36cvss 5.3epss 0.13

    HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

  • CVE-2018-7112MedDec 3, 2018
    risk 0.36cvss 5.5epss 0.01

    The HPE-provided Windows firmware installer for certain Gen9, Gen8, G7,and G6 HPE servers allows local disclosure of privileged information. This issue was resolved in previously provided firmware updates as follows. The HPE Windows firmware installer was updated in the system…

  • CVE-2018-7100MedAug 14, 2018
    risk 0.36cvss 5.5epss 0.01

    A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allow local disclosure of…

  • CVE-2018-7094MedAug 14, 2018
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to allow disclosure of privileged information.

  • CVE-2018-7073MedAug 6, 2018
    risk 0.36cvss 5.5epss 0.01

    A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

  • CVE-2017-5809MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.02

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

  • CVE-2017-5788MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.

  • CVE-2017-5786MedFeb 15, 2018
    risk 0.36cvss 5.5epss 0.01

    A local Unauthorized Data Modification vulnerability in HPE OfficeConnect Network Switches version PT.02.01 including PT.01.03 through PT.01.14

Page 16 of 19