Vendor CVEs
HPE
All CVEs
1,066 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-1988 | Cri | 0.65 | 9.8 | 0.10 | Mar 15, 2016 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989. | ||
| CVE-2026-76674 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2026 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on… | ||
| CVE-2026-76673 | Cri | 0.64 | 9.8 | 0.00 | Sep 15, 2026 | Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges… | ||
| CVE-2026-76672 | Cri | 0.64 | 9.9 | 0.00 | Sep 15, 2026 | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization… | ||
| CVE-2026-76670 | Cri | 0.64 | 9.9 | 0.00 | Sep 15, 2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system… | ||
| CVE-2026-76669 | Cri | 0.64 | 9.9 | 0.00 | Sep 15, 2026 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system… | ||
| CVE-2026-73749 | Cri | 0.64 | 9.8 | 0.00 | Sep 1, 2026 | Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could… | ||
| CVE-2026-63456 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify… | ||
| CVE-2026-63455 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify… | ||
| CVE-2026-23813 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2026 | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password. | ||
| CVE-2026-23600 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | ||
| CVE-2025-37184 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor… | ||
| CVE-2025-37103 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2025 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | ||
| CVE-2025-37099 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2025 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | ||
| CVE-2025-37096 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37095 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37093 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37092 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37090 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37089 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37087 | Cri | 0.64 | 9.8 | 0.00 | Apr 22, 2025 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | ||
| CVE-2024-13804 | Cri | 0.64 | 9.8 | 0.00 | Mar 30, 2025 | Unauthenticated RCE in HPE Insight Cluster Management Utility | ||
| CVE-2024-42395 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2024 | There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete… | ||
| CVE-2024-42394 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system… | ||
| CVE-2024-42393 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system… | ||
| CVE-2024-22442 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | The vulnerability could be remotely exploited to bypass authentication. | ||
| CVE-2024-22441 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | ||
| CVE-2023-30909 | Cri | 0.64 | 9.8 | 0.02 | Sep 14, 2023 | A remote authentication bypass issue exists in some OneView APIs. | ||
| CVE-2023-30908 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. | ||
| CVE-2022-37938 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Unauthenticated server side request forgery in HPE Serviceguard Manager | ||
| CVE-2022-37937 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Pre-auth memory corruption in HPE Serviceguard | ||
| CVE-2022-37936 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Unauthenticated Java deserialization vulnerability in Serviceguard Manager | ||
| CVE-2022-28623 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2022 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL… | ||
| CVE-2022-28620 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2022 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis… | ||
| CVE-2022-28618 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has… | ||
| CVE-2022-28616 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2022-28617 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2022 | A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2021-29215 | Cri | 0.64 | 9.8 | 0.01 | Jan 18, 2022 | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:… | ||
| CVE-2021-26588 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts… | ||
| CVE-2021-26583 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2021 | A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution. | ||
| CVE-2021-25139 | Cri | 0.64 | 9.8 | 0.08 | Feb 9, 2021 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500… | ||
| CVE-2020-7203 | Cri | 0.64 | 9.8 | 0.05 | Dec 18, 2020 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution. | ||
| CVE-2020-7199 | Cri | 0.64 | 9.8 | 0.10 | Dec 2, 2020 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,… | ||
| CVE-2020-7128 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | ||
| CVE-2020-7197 | Cri | 0.64 | 9.8 | 0.02 | Oct 26, 2020 | SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console… | ||
| CVE-2020-7172 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7171 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7170 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7169 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7168 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
- risk 0.65cvss 9.8epss 0.10
HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.
- risk 0.64cvss 9.8epss 0.01
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on…
- risk 0.64cvss 9.8epss 0.00
Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges…
- risk 0.64cvss 9.9epss 0.00
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization…
- risk 0.64cvss 9.9epss 0.00
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system…
- risk 0.64cvss 9.9epss 0.00
Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system…
- risk 0.64cvss 9.8epss 0.00
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could…
- risk 0.64cvss 9.8epss 0.00
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…
- risk 0.64cvss 9.8epss 0.00
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor…
- risk 0.64cvss 9.8epss 0.01
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
- risk 0.64cvss 9.8epss 0.01
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
An authentication bypass vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.00
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated RCE in HPE Insight Cluster Management Utility
- risk 0.64cvss 9.8epss 0.00
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete…
- risk 0.64cvss 9.8epss 0.01
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…
- risk 0.64cvss 9.8epss 0.01
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…
- risk 0.64cvss 9.8epss 0.01
The vulnerability could be remotely exploited to bypass authentication.
- risk 0.64cvss 9.8epss 0.00
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
- risk 0.64cvss 9.8epss 0.02
A remote authentication bypass issue exists in some OneView APIs.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in a OneView API.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated server side request forgery in HPE Serviceguard Manager
- risk 0.64cvss 9.8epss 0.01
Pre-auth memory corruption in HPE Serviceguard
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
- risk 0.64cvss 9.8epss 0.01
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…
- risk 0.64cvss 9.8epss 0.02
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis…
- risk 0.64cvss 9.8epss 0.02
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…
- risk 0.64cvss 9.8epss 0.01
A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.64cvss 9.8epss 0.02
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.64cvss 9.8epss 0.01
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:…
- risk 0.64cvss 9.8epss 0.02
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…
- risk 0.64cvss 9.8epss 0.04
A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.
- risk 0.64cvss 9.8epss 0.08
A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500…
- risk 0.64cvss 9.8epss 0.05
A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.
- risk 0.64cvss 9.8epss 0.10
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,…
- risk 0.64cvss 9.8epss 0.02
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- risk 0.64cvss 9.8epss 0.02
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console…
- risk 0.64cvss 9.8epss 0.07
A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Page 2 of 22