HPE kayıtları
hpe üreticisine ait 277 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %0,7
- Silahlaştırılmış
- 2 · %0,7
- Pre-auth RCE
- 27
- Düzeltme kaydı olan
- %13
- Yayından KEV’e ortanca
- 877 gün
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')35
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')18
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')18
- CWE-287 Improper Authentication16
- CWE-400 Uncontrolled Resource Consumption14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
277 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2017-5689Silahlaştırılmış | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Kritik9,8 | KEV | %92,2 | 2 May 2017 |
96Hemen | CVE-2025-37164Silahlaştırılmış | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Kritik9,8 | KEV | %90,2 | 16 Ara 2025 |
63Bu hafta | CVE-2020-7136Kavram kanıtı | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.hpe · smart update manager | Kritik9,8 | — | %79,5 | 30 Nis 2020 |
56Planlayın | CVE-2024-53676İstismar yok | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.hpe · insight remote support · CWE-552 | Kritik9,8 | — | %56,3 | 26 Kas 2024 |
55Planlayın | CVE-2024-53675İstismar yok | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Yüksek7,5 | — | %83,6 | 26 Kas 2024 |
46Planlayın | CVE-2016-7434Kavram kanıtı | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.ntp · ntp · CWE-20 | Yüksek7,5 | — | %52,9 | 13 Oca 2017 |
44Planlayın | CVE-2024-53674İstismar yok | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Yüksek7,5 | — | %46,7 | 26 Kas 2024 |
42Planlayın | CVE-2025-37098İstismar yok | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.hpe · insight remote support · CWE-22 | Yüksek7,5 | — | %40,0 | 1 Tem 2025 |
40Planlayın | CVE-2018-20732İstismar yok | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.sas · web infrastructure platform · CWE-502 | Kritik9,8 | — | %4,0 | 16 Oca 2019 |
40Planlayın | CVE-2020-24626İstismar yok | Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Uhpe · utility computing service meter · CWE-22 | Kritik9,8 | — | %3,0 | 23 Eyl 2020 |
40Planlayın | CVE-2022-37932Kavram kanıtı | A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.hpe · officeconnect 1820 j9979a firmware | Kritik9,8 | — | %2,7 | 12 Ara 2022 |
40Planlayın | CVE-2019-12002İstismar yok | A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storahpe · msa 1040 firmware | Kritik9,8 | — | %2,2 | 17 Nis 2020 |
40Planlayın | CVE-2022-28618İstismar yok | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrayhpe · nimbleos · CWE-77 | Kritik9,8 | — | %1,8 | 20 May 2022 |
40Planlayın | CVE-2021-26588İstismar yok | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwarhpe · 3par os | Kritik9,8 | — | %1,8 | 11 Eki 2021 |
40Planlayın | CVE-2026-23600İstismar yok | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).hpe · autopass license server · CWE-287 | Kritik10,0 | — | %1,0 | 2 Mar 2026 |
39İzleyin | CVE-2022-28620İstismar yok | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX superhpe · slingshot firmware | Kritik9,8 | — | %1,5 | 24 Haz 2022 |
39İzleyin | CVE-2019-11996İstismar yok | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.hpe · nimbleos | Kritik9,8 | — | %1,5 | 7 Kas 2019 |
39İzleyin | CVE-2019-11988İstismar yok | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.hpe · smart update manager | Kritik9,8 | — | %1,4 | 5 Haz 2019 |
39İzleyin | CVE-2023-30912İstismar yok | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Kritik9,8 | — | %1,2 | 25 Eki 2023 |
39İzleyin | CVE-2025-37091İstismar yok | A command injection remote code execution vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-77 | Kritik9,8 | — | %1,2 | 2 Haz 2025 |
39İzleyin | CVE-2021-29215İstismar yok | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem cohpe · tez | Kritik9,8 | — | %1,2 | 18 Oca 2022 |
39İzleyin | CVE-2025-37093İstismar yok | An authentication bypass vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-287 | Kritik9,8 | — | %1,1 | 2 Haz 2025 |
39İzleyin | CVE-2026-76674İstismar yok | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gatewayshpe · edgeconnect operating system · CWE-120 | Kritik9,8 | — | %1,0 | 15 Eyl 2026 |
39İzleyin | CVE-2022-28623İstismar yok | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.hpe · icewall sso certd · CWE-89 | Kritik9,8 | — | %0,9 | 8 Tem 2022 |
39İzleyin | CVE-2023-39268İstismar yok | Memory Corruption Vulnerability in ArubaOS-Switchhpe · arubaos-switch · CWE-787 | Kritik9,8 | — | %0,8 | 29 Ağu 2023 |
- CVE-2017-568997Hemen
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92intel · active management technology firmware2 May 2017
- CVE-2025-3716496Hemen
A remote code execution issue exists in HPE OneView.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90hpe · oneview16 Ara 2025
- CVE-2020-713663Bu hafta
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.
KritikCVSS 9,8Kavram kanıtıEPSS %80hpe · smart update manager30 Nis 2020
- CVE-2024-5367656Planlayın
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
KritikCVSS 9,8İstismar yokEPSS %56hpe · insight remote support26 Kas 2024
- CVE-2024-5367555Planlayın
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
YüksekCVSS 7,5İstismar yokEPSS %84hpe · insight remote support26 Kas 2024
- CVE-2016-743446Planlayın
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
YüksekCVSS 7,5Kavram kanıtıEPSS %53ntp · ntp13 Oca 2017
- CVE-2024-5367444Planlayın
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
YüksekCVSS 7,5İstismar yokEPSS %47hpe · insight remote support26 Kas 2024
- CVE-2025-3709842Planlayın
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
YüksekCVSS 7,5İstismar yokEPSS %40hpe · insight remote support1 Tem 2025
- CVE-2018-2073240Planlayın
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
KritikCVSS 9,8İstismar yokEPSS %4sas · web infrastructure platform16 Oca 2019
- CVE-2020-2462640Planlayın
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per U
KritikCVSS 9,8İstismar yokEPSS %3hpe · utility computing service meter23 Eyl 2020
- CVE-2022-3793240Planlayın
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.
KritikCVSS 9,8Kavram kanıtıEPSS %3hpe · officeconnect 1820 j9979a firmware12 Ara 2022
- CVE-2019-1200240Planlayın
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Stora
KritikCVSS 9,8İstismar yokEPSS %2hpe · msa 1040 firmware17 Nis 2020
- CVE-2022-2861840Planlayın
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Array
KritikCVSS 9,8İstismar yokEPSS %2hpe · nimbleos20 May 2022
- CVE-2021-2658840Planlayın
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwar
KritikCVSS 9,8İstismar yokEPSS %2hpe · 3par os11 Eki 2021
- CVE-2026-2360040Planlayın
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
KritikCVSS 10,0İstismar yokEPSS %1hpe · autopass license server2 Mar 2026
- CVE-2022-2862039İzleyin
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX super
KritikCVSS 9,8İstismar yokEPSS %2hpe · slingshot firmware24 Haz 2022
- CVE-2019-1199639İzleyin
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.
KritikCVSS 9,8İstismar yokEPSS %1hpe · nimbleos7 Kas 2019
- CVE-2019-1198839İzleyin
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
KritikCVSS 9,8İstismar yokEPSS %1hpe · smart update manager5 Haz 2019
- CVE-2023-3091239İzleyin
A remote code execution issue exists in HPE OneView.
KritikCVSS 9,8İstismar yokEPSS %1hpe · oneview25 Eki 2023
- CVE-2025-3709139İzleyin
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
KritikCVSS 9,8İstismar yokEPSS %1hpe · storeonce system2 Haz 2025
- CVE-2021-2921539İzleyin
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem co
KritikCVSS 9,8İstismar yokEPSS %1hpe · tez18 Oca 2022
- CVE-2025-3709339İzleyin
An authentication bypass vulnerability exists in HPE StoreOnce Software.
KritikCVSS 9,8İstismar yokEPSS %1hpe · storeonce system2 Haz 2025
- CVE-2026-7667439İzleyin
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
KritikCVSS 9,8İstismar yokEPSS %1hpe · edgeconnect operating system15 Eyl 2026
- CVE-2022-2862339İzleyin
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.
KritikCVSS 9,8İstismar yokEPSS %1hpe · icewall sso certd8 Tem 2022
- CVE-2023-3926839İzleyin
Memory Corruption Vulnerability in ArubaOS-Switch
KritikCVSS 9,8İstismar yokEPSS %1hpe · arubaos-switch29 Ağu 2023