Перейти к содержимому
Noroxi

Записи HPE

278 опубликованных записей вендора hpe.

Профиль для исследователя

Попали в KEV
3 · 1,1 %
С эксплойтом
3 · 1,1 %
Pre-auth RCE
27
С записью об исправлении
13,3 %
Медиана: публикация → KEV
1732 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

278 записей
  • CVE-2017-5689
    97Срочно

    An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    intel · active management technology firmware2 мая 2017 г.

  • CVE-2025-37164
    96Срочно

    A remote code execution issue exists in HPE OneView.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %

    hpe · oneview16 дек. 2025 г.

  • CVE-2015-5477
    90Срочно

    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %

    isc · bind29 июл. 2015 г.

  • CVE-2020-7136
    63На этой неделе

    A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.

    КритическаяCVSS 9,8Proof of conceptEPSS 80 %

    hpe · smart update manager30 апр. 2020 г.

  • CVE-2024-53676
    56В плане

    A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

    КритическаяCVSS 9,8Эксплойта нетEPSS 56 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2024-53675
    55В плане

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    ВысокаяCVSS 7,5Эксплойта нетEPSS 84 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2016-7434
    46В плане

    The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

    ВысокаяCVSS 7,5Proof of conceptEPSS 53 %

    ntp · ntp13 янв. 2017 г.

  • CVE-2024-53674
    44В плане

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    ВысокаяCVSS 7,5Эксплойта нетEPSS 47 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2025-37098
    44В плане

    A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 46 %

    hpe · insight remote support1 июл. 2025 г.

  • CVE-2018-20732
    40В плане

    SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    sas · web infrastructure platform16 янв. 2019 г.

  • CVE-2020-24626
    40В плане

    Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per U

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    hpe · utility computing service meter23 сент. 2020 г.

  • CVE-2022-37932
    40В плане

    A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    hpe · officeconnect 1820 j9979a firmware12 дек. 2022 г.

  • CVE-2019-12002
    40В плане

    A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Stora

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    hpe · msa 1040 firmware17 апр. 2020 г.

  • CVE-2022-28618
    40В плане

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Array

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    hpe · nimbleos20 мая 2022 г.

  • CVE-2021-26588
    40В плане

    A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwar

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    hpe · 3par os11 окт. 2021 г.

  • CVE-2026-23600
    40В плане

    A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    hpe · autopass license server2 мар. 2026 г.

  • CVE-2022-28620
    39Наблюдать

    A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX super

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    hpe · slingshot firmware24 июн. 2022 г.

  • CVE-2019-11996
    39Наблюдать

    Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · nimbleos7 нояб. 2019 г.

  • CVE-2019-11988
    39Наблюдать

    A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · smart update manager5 июн. 2019 г.

  • CVE-2023-30912
    39Наблюдать

    A remote code execution issue exists in HPE OneView.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · oneview25 окт. 2023 г.

  • CVE-2025-37091
    39Наблюдать

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · storeonce system2 июн. 2025 г.

  • CVE-2021-29215
    39Наблюдать

    A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem co

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · tez18 янв. 2022 г.

  • CVE-2025-37093
    39Наблюдать

    An authentication bypass vulnerability exists in HPE StoreOnce Software.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · storeonce system2 июн. 2025 г.

  • CVE-2026-76674
    39Наблюдать

    Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · edgeconnect operating system15 сент. 2026 г.

  • CVE-2022-28623
    39Наблюдать

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hpe · icewall sso certd8 июл. 2022 г.