← Back

Hpe

hpe

183 CVEs • 557 products

Products (557)

Click to collapse
Toggle
Arubaos Cx
arubaos-cx
Hpux Ntp
hpux-ntp
Nimbleos
nimbleos
Hf20 Firmware
hf20_firmware
Hf40 Firmware
hf40_firmware
Hf60 Firmware
hf60_firmware
Oneview
oneview
Web Viewpoint
web_viewpoint

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hpe
2Agentless Management
Proliant Agentless Management
Jun 17, 2026
Feb 4, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user wi...Show more
A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0, 10.96.0.0. This vulnerability could be exploited locally by a user with high privileges to execute malware that may lead to a loss of confidentiality, integrity, and availability. HPE has provided software updates to resolve the vulnerability in HPE Agentless Management Service for Windows.Show less
1Hpe
1Tez
Jun 17, 2026
Jan 18, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.20190708110...Show more
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9: mapr-tez-0.9.201907090334-1.noarch; prior to Tez-0.9.2: mapr-tez-0.9.2.0.201907081043-1.noarch. HPE has provided software updates to resolve the vulnerability in the TEZ MapR ecosystem component in HPE Ezmeral Data Fabric.Show less
6Balasys
F5Hpe+3 more
30Arubaos Cx
Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+27 more
Aug 22, 2025
Nov 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculati...Show more
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.Show less
1Hpe
3Proliant Dl20 Gen10 Server Firmware
Proliant Microserver Gen10 Plus FirmwareProliant Ml30 Gen10 Server Firmware
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs prior to version 2.52....Show more
A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProLiant MicroServer Gen10 Plus server's system ROMs prior to version 2.52. The vulnerability could be locally exploited to cause disclosure of sensitive information, denial of service (DoS), and/or compromise system integrity.Show less
1Hpe
2Superdome Flex 280 Firmware
Superdome Flex Firmware
Jun 17, 2026
Oct 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly At...Show more
A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Site Scripting (XSS) because the Session Cookie is missing an HttpOnly Attribute. HPE has provided a firmware update to resolve the vulnerability in HPE Superdome Flex Servers.Show less
1Hpe
63par Os
Alletra 9060 FirmwareAlletra 9080 Firmware+3 more
Jun 17, 2026
Oct 11, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to ex...Show more
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity, availability of the array. HPE has made the following software updates and mitigation information to resolve the vulnerability in 3PAR, Primera and Alletra 9000 firmware.Show less
1Hpe
6Storeonce 3620 Firmware
Storeonce 3640 FirmwareStoreonce 5200 Firmware+3 more
Jun 17, 2026
Sep 27, 2021
N/A· v4
6.5 MEDIUM· v3
6.0 MEDIUM· v2
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confid...Show more
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integrity. HPE has made the following software update - HPE StoreOnce 4.3.0, to resolve the vulnerability in HPE StoreOnce.Show less
2Etinet
Hpe
2Backbox E4.09 Firmware
Backbox H4.09 Firmware
Jun 17, 2026
Jun 25, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verif...Show more
ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verifying the Password returns 0 (no error). The reason is that the user is not running the XYGate application. Hence, BBSV assumes the Password is correct. For H4.09, the affected version isT0954V04^AAO. For E4.09, the affected version is 22SEP2020. Note: If your current version is E4.10-16MAY2021 (version procedure T9999V04_16MAY2022_BPAKETI_10), a hotfix (FIXPAK-19OCT-2022) is available in version E4.10-19OCT2022. Resolution to CVE-2021-33895 in version E4.11-19OCT2022Show less
1Hpe
1Oneview Global Dashboard
Jun 17, 2026
Jun 24, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The iss...Show more
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.Show less
1Hpe
1Superdome Flex Server Firmware
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be reboote...Show more
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. Other BMC management is not impacted. HPE has made the following software update to resolve the vulnerability in HPE Superdome Flex Server: Superdome Flex Server Firmware 3.30.142 or later.Show less
1Hpe
1Integrated Lights Out Amplifier
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resol...Show more
A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amplifier Pack: HPE iLO Amplifier Pack 1.95 or later.Show less
1Hpe
1Unified Data Management
Jun 17, 2026
Mar 30, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1...Show more
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM). Version 1.2103.0 of HPE Unified Data Management (UDM) removes all hard-coded cryptographic keys.Show less
1Hpe
1Network Orchestrator
Jun 17, 2026
Mar 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.
1Hpe
1Web Viewpoint
Jun 17, 2026
Feb 9, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AAR through T0952L01^AAX, and T0986L01^AAD through T0986L01^AAJ (L) and T...Show more
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AAR through T0952L01^AAX, and T0986L01^AAD through T0986L01^AAJ (L) and T0320H01^ABW through T0320H01^ACC, T0952H01^AAQ through T0952H01^AAW, and T0986H01^AAC through T0986H01^AAI (J and H).Show less
1Hpe
1Web Viewpoint
Jun 17, 2026
Feb 9, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, an...Show more
Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AAH through T0952L01^AAR, T0986L01 through T0986L01^AAF, T0665L01^AAP, and T0662L01^AAP (L) and T0320H01^ABO through T0320H01^ABY, T0952H01^AAG through T0952H01^AAQ, T0986H01 through T0986H01^AAE, T0665H01^AAO, and T0662H01^AAO (J and H).Show less
2Arubanetworks
Hpe
153500 Firmware
3500 Yl Firmware6200 Yl Firmware+12 more
Jun 17, 2026
Feb 9, 2021
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's man...Show more
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability.Show less
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.
1Hpe
1Baseboard Management Controller
Jun 17, 2026
Feb 8, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.