Записи HPE
278 опубликованных записей вендора hpe.
Профиль для исследователя
- Попали в KEV
- 3 · 1,1 %
- С эксплойтом
- 3 · 1,1 %
- Pre-auth RCE
- 27
- С записью об исправлении
- 13,3 %
- Медиана: публикация → KEV
- 1732 дн.
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')35
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')18
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')18
- CWE-287 Improper Authentication16
- CWE-400 Uncontrolled Resource Consumption14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
278 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2017-5689Готовый эксплойт | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Критическая9,8 | KEV | 92,2 % | 2 мая 2017 г. |
96Срочно | CVE-2025-37164Готовый эксплойт | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Критическая9,8 | KEV | 90,2 % | 16 дек. 2025 г. |
90Срочно | CVE-2015-5477Готовый эксплойт | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Высокая7,5 | KEV | 99,4 % | 29 июл. 2015 г. |
63На этой неделе | CVE-2020-7136Proof of concept | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.hpe · smart update manager | Критическая9,8 | — | 79,5 % | 30 апр. 2020 г. |
56В плане | CVE-2024-53676Эксплойта нет | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.hpe · insight remote support · CWE-552 | Критическая9,8 | — | 56,3 % | 26 нояб. 2024 г. |
55В плане | CVE-2024-53675Эксплойта нет | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Высокая7,5 | — | 83,6 % | 26 нояб. 2024 г. |
46В плане | CVE-2016-7434Proof of concept | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.ntp · ntp · CWE-20 | Высокая7,5 | — | 53,1 % | 13 янв. 2017 г. |
44В плане | CVE-2024-53674Эксплойта нет | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Высокая7,5 | — | 46,7 % | 26 нояб. 2024 г. |
44В плане | CVE-2025-37098Эксплойта нет | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.hpe · insight remote support · CWE-22 | Высокая7,5 | — | 46,3 % | 1 июл. 2025 г. |
40В плане | CVE-2018-20732Эксплойта нет | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.sas · web infrastructure platform · CWE-502 | Критическая9,8 | — | 4,0 % | 16 янв. 2019 г. |
40В плане | CVE-2020-24626Эксплойта нет | Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Uhpe · utility computing service meter · CWE-22 | Критическая9,8 | — | 3,0 % | 23 сент. 2020 г. |
40В плане | CVE-2022-37932Proof of concept | A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.hpe · officeconnect 1820 j9979a firmware | Критическая9,8 | — | 2,8 % | 12 дек. 2022 г. |
40В плане | CVE-2019-12002Эксплойта нет | A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storahpe · msa 1040 firmware | Критическая9,8 | — | 2,2 % | 17 апр. 2020 г. |
40В плане | CVE-2022-28618Эксплойта нет | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrayhpe · nimbleos · CWE-77 | Критическая9,8 | — | 1,8 % | 20 мая 2022 г. |
40В плане | CVE-2021-26588Эксплойта нет | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwarhpe · 3par os | Критическая9,8 | — | 1,8 % | 11 окт. 2021 г. |
40В плане | CVE-2026-23600Эксплойта нет | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).hpe · autopass license server · CWE-287 | Критическая10,0 | — | 1,0 % | 2 мар. 2026 г. |
39Наблюдать | CVE-2022-28620Эксплойта нет | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX superhpe · slingshot firmware | Критическая9,8 | — | 1,5 % | 24 июн. 2022 г. |
39Наблюдать | CVE-2019-11996Эксплойта нет | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.hpe · nimbleos | Критическая9,8 | — | 1,5 % | 7 нояб. 2019 г. |
39Наблюдать | CVE-2019-11988Эксплойта нет | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.hpe · smart update manager | Критическая9,8 | — | 1,4 % | 5 июн. 2019 г. |
39Наблюдать | CVE-2023-30912Эксплойта нет | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Критическая9,8 | — | 1,2 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2025-37091Эксплойта нет | A command injection remote code execution vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-77 | Критическая9,8 | — | 1,2 % | 2 июн. 2025 г. |
39Наблюдать | CVE-2021-29215Эксплойта нет | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem cohpe · tez | Критическая9,8 | — | 1,2 % | 18 янв. 2022 г. |
39Наблюдать | CVE-2025-37093Эксплойта нет | An authentication bypass vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-287 | Критическая9,8 | — | 1,1 % | 2 июн. 2025 г. |
39Наблюдать | CVE-2026-76674Эксплойта нет | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gatewayshpe · edgeconnect operating system · CWE-120 | Критическая9,8 | — | 1,0 % | 15 сент. 2026 г. |
39Наблюдать | CVE-2022-28623Эксплойта нет | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.hpe · icewall sso certd · CWE-89 | Критическая9,8 | — | 0,9 % | 8 июл. 2022 г. |
- CVE-2017-568997Срочно
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %intel · active management technology firmware2 мая 2017 г.
- CVE-2025-3716496Срочно
A remote code execution issue exists in HPE OneView.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %hpe · oneview16 дек. 2025 г.
- CVE-2015-547790Срочно
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %isc · bind29 июл. 2015 г.
- CVE-2020-713663На этой неделе
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.
КритическаяCVSS 9,8Proof of conceptEPSS 80 %hpe · smart update manager30 апр. 2020 г.
- CVE-2024-5367656В плане
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 56 %hpe · insight remote support26 нояб. 2024 г.
- CVE-2024-5367555В плане
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
ВысокаяCVSS 7,5Эксплойта нетEPSS 84 %hpe · insight remote support26 нояб. 2024 г.
- CVE-2016-743446В плане
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
ВысокаяCVSS 7,5Proof of conceptEPSS 53 %ntp · ntp13 янв. 2017 г.
- CVE-2024-5367444В плане
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
ВысокаяCVSS 7,5Эксплойта нетEPSS 47 %hpe · insight remote support26 нояб. 2024 г.
- CVE-2025-3709844В плане
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
ВысокаяCVSS 7,5Эксплойта нетEPSS 46 %hpe · insight remote support1 июл. 2025 г.
- CVE-2018-2073240В плане
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sas · web infrastructure platform16 янв. 2019 г.
- CVE-2020-2462640В плане
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per U
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %hpe · utility computing service meter23 сент. 2020 г.
- CVE-2022-3793240В плане
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %hpe · officeconnect 1820 j9979a firmware12 дек. 2022 г.
- CVE-2019-1200240В плане
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Stora
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hpe · msa 1040 firmware17 апр. 2020 г.
- CVE-2022-2861840В плане
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Array
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hpe · nimbleos20 мая 2022 г.
- CVE-2021-2658840В плане
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwar
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hpe · 3par os11 окт. 2021 г.
- CVE-2026-2360040В плане
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %hpe · autopass license server2 мар. 2026 г.
- CVE-2022-2862039Наблюдать
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX super
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hpe · slingshot firmware24 июн. 2022 г.
- CVE-2019-1199639Наблюдать
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · nimbleos7 нояб. 2019 г.
- CVE-2019-1198839Наблюдать
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · smart update manager5 июн. 2019 г.
- CVE-2023-3091239Наблюдать
A remote code execution issue exists in HPE OneView.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · oneview25 окт. 2023 г.
- CVE-2025-3709139Наблюдать
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · storeonce system2 июн. 2025 г.
- CVE-2021-2921539Наблюдать
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem co
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · tez18 янв. 2022 г.
- CVE-2025-3709339Наблюдать
An authentication bypass vulnerability exists in HPE StoreOnce Software.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · storeonce system2 июн. 2025 г.
- CVE-2026-7667439Наблюдать
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · edgeconnect operating system15 сент. 2026 г.
- CVE-2022-2862339Наблюдать
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hpe · icewall sso certd8 июл. 2022 г.