VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2025-37111MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2025-37110MedJul 31, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

  • CVE-2025-27080MedMar 18, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to…

  • CVE-2018-12181MedMar 27, 2019
    risk 0.39cvss 6.0epss 0.00

    Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.

  • CVE-2018-7108MedSep 27, 2018
    risk 0.39cvss 5.9epss 0.02

    HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific…

  • CVE-2016-9042MedJun 4, 2018
    risk 0.39cvss 5.9epss 0.04

    An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will…

  • CVE-2017-14360MedNov 8, 2017
    risk 0.39cvss 5.9epss 0.02

    A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).

  • CVE-2026-76702MedSep 15, 2026
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable…

  • CVE-2026-76701MedSep 15, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain…

  • CVE-2026-76700MedSep 15, 2026
    risk 0.38cvss 5.9epss 0.00

    Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.

  • CVE-2025-37159MedNov 18, 2025
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially…

  • CVE-2024-24455MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

  • CVE-2024-24453MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a…

  • CVE-2024-24452MedNov 15, 2024
    risk 0.38cvss 5.9epss 0.00

    An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

  • CVE-2024-5486MedJul 30, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further…

  • CVE-2021-22267MedFeb 9, 2021
    risk 0.38cvss 5.9epss 0.01

    Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY,…

  • CVE-2019-11989MedJul 19, 2019
    risk 0.38cvss 5.9epss 0.02

    A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for…

  • CVE-2019-5392MedJun 5, 2019
    risk 0.38cvss 5.3epss 0.07

    A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7110MedOct 17, 2018
    risk 0.38cvss 5.9epss 0.01

    A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.

  • CVE-2016-1987MedFeb 18, 2016
    risk 0.38cvss 5.9epss 0.02

    HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

  • CVE-2026-73755MedSep 1, 2026
    risk 0.37cvss 5.7epss 0.00

    A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable system.

  • CVE-2026-76705MedSep 15, 2026
    risk 0.36cvss 5.5epss 0.01

    A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.

  • CVE-2026-76704MedSep 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an…

  • CVE-2026-76703MedSep 15, 2026
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to…

  • CVE-2026-73732MedSep 1, 2026
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to obtain sensitive information. Successful exploitation could allow an attacker to retrieve sensitive data which could…

  • CVE-2025-37185MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2025-37094MedJun 2, 2025
    risk 0.36cvss 5.5epss 0.01

    A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-25041MedApr 1, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft…

  • CVE-2025-23057MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23056MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2025-23055MedJan 28, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web…

  • CVE-2024-51765MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

  • CVE-2024-51764MedNov 15, 2024
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.

  • CVE-2024-42508MedOct 18, 2024
    risk 0.36cvss 5.5epss 0.00

    This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

  • CVE-2023-6573MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    HPE OneView may have a missing passphrase during restore.

  • CVE-2023-30904MedJun 16, 2023
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.

  • CVE-2023-30903MedJun 16, 2023
    risk 0.36cvss 5.5epss 0.00

    HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.

  • CVE-2023-28084MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens

  • CVE-2023-28090MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose SNMPv3 read credentials

  • CVE-2023-28087MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose OneView user accounts

  • CVE-2023-28086MedApr 25, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView appliance dump may expose proxy credential settings

  • CVE-2023-28091MedApr 14, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump

  • CVE-2023-28085MedApr 14, 2023
    risk 0.36cvss 5.5epss 0.00

    An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials

  • CVE-2022-37935MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.

  • CVE-2022-28625MedAug 31, 2022
    risk 0.36cvss 5.5epss 0.00

    A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality,…

  • CVE-2022-23700MedApr 4, 2022
    risk 0.36cvss 5.5epss 0.00

    A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-26585MedJun 24, 2021
    risk 0.36cvss 5.5epss 0.00

    A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.

  • CVE-2021-26579MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM).…

  • CVE-2019-11998MedJan 16, 2020
    risk 0.36cvss 5.5epss 0.01

    HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information…

  • CVE-2018-7115MedDec 3, 2018
    risk 0.36cvss 5.3epss 0.06

    HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions.

Page 18 of 22