← Back

Hpe

hpe

183 CVEs • 557 products

Products (557)

Click to collapse
Toggle
Arubaos Cx
arubaos-cx
Hpux Ntp
hpux-ntp
Nimbleos
nimbleos
Hf20 Firmware
hf20_firmware
Hf40 Firmware
hf40_firmware
Hf60 Firmware
hf60_firmware
Oneview
oneview
Web Viewpoint
web_viewpoint

CVEs (183)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hpe
1Superdome Flex Server Firmware
Jun 17, 2026
Jan 16, 2020
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and acce...Show more
HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information disclosure, or denial of service. HPE has provided firmware updates that address the above vulnerabilities for the HPE Superdome Flex Server starting with firmware version v3.20.186 (not available online) and v3.20.206 (available online). Apply v3.20.206 (4 December 2019) or a newer version to resolve this issue. Please visit HPE Support Center https://support.hpe.com/hpesc/public/home to obtain the updated firmware for your product.Show less
2Hpe
Intel
284Apollo 4200 Gen10 Server Firmware
Apollo 4200 Gen9 Server FirmwareAtom C2308 Firmware+281 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
8.2 HIGH· v3
4.6 MEDIUM· v2
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Inte...Show more
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.Show less
2Hpe
Intel
284Apollo 4200 Gen10 Server Firmware
Apollo 4200 Gen9 Server FirmwareAtom C2308 Firmware+281 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potenti...Show more
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.Show less
1Hpe
1Nimbleos
Jun 17, 2026
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array....Show more
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.Show less
1Hpe
1Smart Update Manager
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
1Hpe
1Smart Update Manager
Jun 17, 2026
Jun 5, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege.
5Fedoraproject
HpeNetapp+2 more
6Clustered Data Ontap
Data OntapFedora+3 more
Jun 17, 2026
May 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NTP through 4.2.8p12 has a NULL Pointer Dereference.
10Canonical
DebianHp+7 more
32Active Iq Unified Manager
Cloud BackupDebian Linux+29 more
Jun 17, 2026
Feb 4, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
1Hpe
1Service Governance Framework
Jun 17, 2026
Oct 17, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different para...Show more
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.Show less
1Hpe
1Storageworks Xp7 Automation Director
Jun 17, 2026
Sep 27, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage syst...Show more
HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerability that exposed the user authentication information of the storage system. This problem sometimes occurred under specific conditions when running a service template.Show less
1Hpe
1Device Entitlement Gateway
Jun 17, 2026
Sep 27, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privileg...Show more
A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege.Show less
1Hpe
13par Service Provider
Jun 17, 2026
Aug 14, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to allow disclosure of privileged information.
1Hpe
1Arubaos
Jan 7, 2025
Aug 6, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the abilit...Show more
Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the ability to execute arbitrary code - remote code execution has not yet been confirmed.Show less
4Freebsd
HpeNtp+1 more
4Freebsd
Hpux NtpNtp+1 more
Nov 21, 2024
Jun 4, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for...Show more
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.Show less
6Canonical
HpeNetapp+3 more
16Diskstation Manager
Fujitsu M10 1 FirmwareFujitsu M10 4 Firmware+13 more
Jun 17, 2026
Mar 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side"...Show more
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.Show less
4Hpe
NetappNtp+1 more
9Diskstation Manager
HciHpux Ntp+6 more
Jun 17, 2026
Mar 6, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and mo...Show more
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.Show less
3Hpe
IntelSiemens
36Active Management Technology Firmware
Proliant Ml10 Gen9 Server FirmwareSimatic Field Pg M3 Firmware+33 more
Apr 22, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could...Show more
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).Show less
4Apple
HpeNtp+1 more
4Hpux Ntp
Mac Os XNtp+1 more
May 13, 2026
Mar 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
2Hpe
Ntp
2Hpux Ntp
Ntp
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
4Canonical
HpeNtp+1 more
9Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+6 more
May 13, 2026
Jan 13, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sou...Show more
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.Show less