Vendor CVEs
HPE
All CVEs
938 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63455 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify… | ||
| CVE-2026-23813 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2026 | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password. | ||
| CVE-2026-23600 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | ||
| CVE-2025-37184 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2026 | A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor… | ||
| CVE-2025-37103 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2025 | Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system. | ||
| CVE-2025-37099 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2025 | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | ||
| CVE-2025-37096 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37095 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37093 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37092 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37090 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A server-side request forgery vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37089 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | A command injection remote code execution vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2025-37087 | Cri | 0.64 | 9.8 | 0.00 | Apr 22, 2025 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | ||
| CVE-2024-13804 | Cri | 0.64 | 9.8 | 0.00 | Mar 30, 2025 | Unauthenticated RCE in HPE Insight Cluster Management Utility | ||
| CVE-2024-42395 | Cri | 0.64 | 9.8 | 0.00 | Aug 6, 2024 | There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete… | ||
| CVE-2024-42394 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system… | ||
| CVE-2024-42393 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system… | ||
| CVE-2024-22442 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | The vulnerability could be remotely exploited to bypass authentication. | ||
| CVE-2024-22441 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | ||
| CVE-2023-30909 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2023 | A remote authentication bypass issue exists in some OneView APIs. | ||
| CVE-2023-30908 | Cri | 0.64 | 9.8 | 0.01 | Sep 7, 2023 | A remote authentication bypass issue exists in a OneView API. | ||
| CVE-2022-37938 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Unauthenticated server side request forgery in HPE Serviceguard Manager | ||
| CVE-2022-37937 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Pre-auth memory corruption in HPE Serviceguard | ||
| CVE-2022-37936 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2023 | Unauthenticated Java deserialization vulnerability in Serviceguard Manager | ||
| CVE-2022-28623 | Cri | 0.64 | 9.8 | 0.01 | Jul 8, 2022 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL… | ||
| CVE-2022-28620 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2022 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis… | ||
| CVE-2022-28618 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has… | ||
| CVE-2022-28616 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2022 | A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2022-28617 | Cri | 0.64 | 9.8 | 0.02 | May 17, 2022 | A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. | ||
| CVE-2021-29215 | Cri | 0.64 | 9.8 | 0.01 | Jan 18, 2022 | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:… | ||
| CVE-2021-26588 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts… | ||
| CVE-2021-26583 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2021 | A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution. | ||
| CVE-2021-25139 | Cri | 0.64 | 9.8 | 0.08 | Feb 9, 2021 | A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500… | ||
| CVE-2020-7203 | Cri | 0.64 | 9.8 | 0.05 | Dec 18, 2020 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution. | ||
| CVE-2020-7199 | Cri | 0.64 | 9.8 | 0.09 | Dec 2, 2020 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,… | ||
| CVE-2020-7128 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2020 | A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. | ||
| CVE-2020-7197 | Cri | 0.64 | 9.8 | 0.02 | Oct 26, 2020 | SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console… | ||
| CVE-2020-7172 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7171 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7170 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7169 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7168 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7167 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7166 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A operatorgrouptreeselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7165 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7164 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A operationselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7163 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A navigationto expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7162 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7161 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | ||
| CVE-2020-7160 | Cri | 0.64 | 9.8 | 0.07 | Oct 19, 2020 | A iccselectdeviceseries expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
- risk 0.64cvss 9.8epss 0.00
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor…
- risk 0.64cvss 9.8epss 0.01
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
- risk 0.64cvss 9.8epss 0.01
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
An authentication bypass vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A server-side request forgery vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.00
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated RCE in HPE Insight Cluster Management Utility
- risk 0.64cvss 9.8epss 0.00
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete…
- risk 0.64cvss 9.8epss 0.01
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…
- risk 0.64cvss 9.8epss 0.01
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…
- risk 0.64cvss 9.8epss 0.01
The vulnerability could be remotely exploited to bypass authentication.
- risk 0.64cvss 9.8epss 0.00
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in some OneView APIs.
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass issue exists in a OneView API.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated server side request forgery in HPE Serviceguard Manager
- risk 0.64cvss 9.8epss 0.01
Pre-auth memory corruption in HPE Serviceguard
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
- risk 0.64cvss 9.8epss 0.01
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…
- risk 0.64cvss 9.8epss 0.01
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis…
- risk 0.64cvss 9.8epss 0.02
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…
- risk 0.64cvss 9.8epss 0.01
A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.64cvss 9.8epss 0.02
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
- risk 0.64cvss 9.8epss 0.01
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:…
- risk 0.64cvss 9.8epss 0.02
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…
- risk 0.64cvss 9.8epss 0.04
A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.
- risk 0.64cvss 9.8epss 0.08
A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500…
- risk 0.64cvss 9.8epss 0.05
A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.
- risk 0.64cvss 9.8epss 0.09
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,…
- risk 0.64cvss 9.8epss 0.02
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- risk 0.64cvss 9.8epss 0.02
SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console…
- risk 0.64cvss 9.8epss 0.07
A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A operatorgrouptreeselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A operationselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A navigationto expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
- risk 0.64cvss 9.8epss 0.07
A iccselectdeviceseries expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
Page 2 of 19