-Infinity
0

Vendor Risk Score

See how hpe compares to other vendors in security performance

View Risk Score →

Software

hpe aruba cx 10000-48y6c \(r8p13a\)
36
hpe aruba cx 10000-48y6c \(r8p14a\)
36
hpe aruba cx 10000-48y6c \(s0f98a\)
36
hpe aruba cx 10040 32p \(s4r54a\)
36
hpe aruba cx 10040 32p \(s4r55a\)
36
hpe aruba cx 10040 32p \(s4r56a\)
36
hpe aruba cx 10040 \(s4r58a\)
36
hpe aruba cx 4100i 12-port \(jl817a\)
36
hpe aruba cx 4100i 24-port \(jl818a\)
36
hpe aruba cx 6000 12g \(r8n89a\)
34
hpe aruba cx 6000 12p \(r8n89b\)
34
hpe aruba cx 6000 12p \(s4r21a\)
34
hpe aruba cx 6000 24g \(r8n87a\)
34
hpe aruba cx 6000 24g \(r8n88a\)
34
hpe aruba cx 6000 24p \(r8n87b\)
34
hpe aruba cx 6000 24p \(r8n88b\)
34
hpe aruba cx 6000 24p \(s4r26a\)
34
hpe aruba cx 6000 24p \(s4r27a\)
34
hpe aruba cx 6000 48g \(r8n85a\)
34
hpe aruba cx 6000 48g \(r8n86a\)
34
hpe aruba cx 6000 48g \(r9y03a\)
34
hpe aruba cx 6000 48p \(r8n85b\)
34
hpe aruba cx 6000 48p \(r8n86b\)
34
hpe aruba cx 6000 48p \(r9y03b\)
34
hpe aruba cx 6000 48p \(s4r20a\)
34
hpe aruba cx 6000 48p \(s4r24a\)
34
hpe aruba cx 6000 48p \(s4r25a\)
34
hpe aruba cx 6000 8p \(s4r22a\)
34
hpe aruba cx 6000 8p \(s4r23a\)
34
hpe aruba cx 6000 8p \(s4r28a\)
34
hpe aruba cx 6000 8p \(s4r29a\)
34
hpe aruba cx 6100 12g \(jl679a\)
34
hpe aruba cx 6100 24g \(jl677a\)
34
hpe aruba cx 6100 24g \(jl678a\)
34
hpe aruba cx 6100 48g \(jl675a\)
34
hpe aruba cx 6100 48g \(jl676a\)
34
hpe aruba cx 6100 48g \(r9y04a\)
34
hpe aruba cx 6200f 12g \(r8q72a\)
34
hpe aruba cx 6200f 12g \(r8v13a\)
34
hpe aruba cx 6200f 24g \(jl724b\)
34
hpe aruba cx 6200f 24g \(jl725b\)
34
hpe aruba cx 6200f 24g \(s0g13a\)
34
hpe aruba cx 6200f 24g \(s0g14a\)
34
hpe aruba cx 6200f 24g \(s0m81a\)
34
hpe aruba cx 6200f 24g \(s0m82a\)
34
hpe aruba cx 6200f 24g \(s0m86a\)
34
hpe aruba cx 6200f 24g \(s0m87a\)
34
hpe aruba cx 6200f 48g \(jl726b\)
34
hpe aruba cx 6200f 48g \(jl727b\)
34
hpe aruba cx 6200f 48g \(jl728b\)
34
Severity
10
Code Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

A remote code execution issue exists in HPE OneView.

1 / 2
Source: NVD
First published (updated )
Severity
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A remote authentication bypass vulnerability

exists in HPE AutoPass License Server (APLS).

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at https://support.hpe.com/hpesc/public/home to download the latest version of HPE Smart Update Manager (SUM). Download the latest version of HPE Smart Update Manager (SUM) or download the latest Service Pack For ProLiant (SPP).

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

First published (updated )
Severity
9.8
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Unauthenticated RCE in HPE Insight Cluster Management Utility

First published (updated )
Severity
9.8
EPSS
0.05%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.

First published (updated )
Severity
9.8
Command Injection
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
SSRF
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An authentication bypass vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
Command Injection
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
Path Traversal
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
Command Injection
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

First published (updated )
Severity
9.8
Code Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

First published (updated )
Severity
9.8
Code Injection
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203