VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2026-73754MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Denial-of-service vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation could allow an authenticated user to disrupt the normal operation of a vulnerable system.

  • CVE-2026-73736MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

  • CVE-2026-23822MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to…

  • CVE-2025-37178MedJan 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific…

  • CVE-2025-37160MedNov 18, 2025
    risk 0.34cvss 5.3epss 0.00

    A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.

  • CVE-2024-42400MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42399MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42398MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42397MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42396MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-31479MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2022-37940MedMar 22, 2023
    risk 0.34cvss 5.3epss 0.00

    Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE…

  • CVE-2019-5394MedJun 5, 2019
    risk 0.33cvss 5.1epss 0.00

    The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

  • CVE-2026-73783MedSep 1, 2026
    risk 0.32cvss 4.9epss 0.00

    Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.

  • CVE-2026-44874MedMay 12, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of…

  • CVE-2025-37131MedSep 16, 2025
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

  • CVE-2025-27085MedApr 8, 2025
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an…

  • CVE-2024-31483MedMay 14, 2024
    risk 0.32cvss 4.9epss 0.00

    An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

  • CVE-2026-73738MedSep 1, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the underlying operating system of HPE Networking Fabric Composer could allow an authenticated low privilege operator user with local access to view sensitive information. Successful exploitation could allow an attacker to retrieve information which could be…

  • CVE-2026-73737MedSep 1, 2026
    risk 0.31cvss 4.8epss 0.00

    An unauthenticated path traversal vulnerability exists in the API endpoint of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to manipulate user generated files, potentially leading to unauthorized changes in critical…

  • CVE-2025-25039MedFeb 4, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower…

  • CVE-2024-53672MedDec 3, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the…

  • CVE-2024-51773MedDec 3, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the…

  • CVE-2022-28624MedJul 8, 2022
    risk 0.31cvss 4.8epss 0.00

    A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE…

  • CVE-2021-29211MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29210MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29209MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29208MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity…

  • CVE-2021-29207MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29206MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29205MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29204MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2021-29201MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

  • CVE-2019-5403MedAug 9, 2019
    risk 0.31cvss 4.8epss 0.01

    A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2026-73740MedSep 1, 2026
    risk 0.29cvss 4.4epss 0.00

    A local privilege escalation vulnerability in HPE Networking Fabric Composer could allow an authenticated privileged user on the underlying host to elevate their user privileges to those of a higher role. A successful exploit allows the attacker to change the state of certain…

  • CVE-2026-73739MedSep 1, 2026
    risk 0.29cvss 4.4epss 0.00

    A vulnerability exists in the API of HPE Networking Fabric Composer that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve sensitive information that was expected to…

  • CVE-2024-58005MedFeb 27, 2025
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tpm: Change to kvalloc() in eventlog/acpi.c The following failure was reported on HPE ProLiant D320: [ 10.693310][ T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0) [ 10.848132][ T1]…

  • CVE-2023-39268MedAug 29, 2023
    risk 0.29cvss 4.5epss 0.01

    A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying…

  • CVE-2021-25141MedFeb 9, 2021
    risk 0.29cvss 4.4epss 0.00

    A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing…

  • CVE-2016-4381MedSep 8, 2016
    risk 0.29cvss 4.5epss 0.00

    HPE XP7 Command View Advanced Edition (CVAE) Suite 6.x through 8.x before 8.4.1-02, when Replication Manager (RepMgr) and Device Manager (DevMgr) are enabled, allows local users to bypass intended access restrictions via unspecified vectors.

  • CVE-2026-76707MedSep 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of…

  • CVE-2026-73742MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to their requests. Successful exploitation could allow an attacker to cause inaccurate attribution information to…

  • CVE-2026-73741MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation could allow an attacker to access limited data beyond what is authorized by the user's existing privilege…

  • CVE-2026-23812MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of data streams, allowing for…

  • CVE-2026-23811MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - when combined with a…

  • CVE-2026-23810MedMar 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with…

  • CVE-2025-25042MedMar 18, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further…

  • CVE-2024-42504MedOct 3, 2024
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.

  • CVE-2019-5393MedJun 5, 2019
    risk 0.28cvss 4.3epss 0.02

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2019-7317MedFeb 4, 2019
    risk 0.28cvss 5.3epss 0.09

    png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.