Hewlett Packard Enterprise Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Hewlett Packard Enterprise products.
Products
- Intelligent Management Center (iMC) PLAT95 vulnerabilities
- Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central16 vulnerabilities
- Matrix Operating Environment15 vulnerabilities
- Aruba ClearPass Policy Manager11 vulnerabilities
- System Management Homepage for Windows and Linux9 vulnerabilities
- HPE 3PAR Service Processors7 vulnerabilities
- HPE AutoPass License Server7 vulnerabilities
- Network Automation6 vulnerabilities
- HPE CentralView Fraud Risk Management5 vulnerabilities
- HPE Intelligent Management Center (IMC)5 vulnerabilities
- Aruba ClearPass4 vulnerabilities
- HP Network Node Manager (NNMi)4 vulnerabilities
- HPE OneView4 vulnerabilities
- SiteScope4 vulnerabilities
- Version Control Repository Manager (VCRM)4 vulnerabilities
- ArubaOS-Switch3 vulnerabilities
- Data Protector3 vulnerabilities
- HP Keyview3 vulnerabilities
- HPE Aruba Networking EdgeConnect SD-WAN Orchestrator3 vulnerabilities
- HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 103 vulnerabilities
- HPE Telco Network Function Virtual Orchestrator3 vulnerabilities
- Insight Remote Support3 vulnerabilities
- Moonshot Provisioning Manager Appliance3 vulnerabilities
- Systems Insight Manager using OpenSSL3 vulnerabilities
- Aruba AirWave2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-37112MEDIUM | Hard-Coded Encryption Keys found in SystemA vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. CWE-798Jul 31, 2025 | CVSS6.0v3.1 | EPSS0.085% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37111MEDIUM | Hard-Coded Authentication Keys found in SystemA vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. CWE-798Jul 31, 2025 | CVSS6.0v3.1 | EPSS0.148% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37110MEDIUM | Sensitive Credential Information stored insecurely in System DatabaseA vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. CWE-922Jul 31, 2025 | CVSS6.0v3.1 | EPSS0.136% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37107HIGH | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. CWE-287Jul 16, 2025 | CVSS7.3v3.1 | EPSS0.421% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37106HIGH | An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. CWE-287Jul 16, 2025 | CVSS7.3v3.1 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37105HIGH | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. CWE-94Jul 16, 2025 | CVSS7.5v3.1 | EPSS0.602% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-51770HIGH | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. CWE-497Jul 14, 2025 | CVSS7.5v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-51769HIGH | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. CWE-200Jul 14, 2025 | CVSS7.5v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-51768HIGH | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. CWE-94Jul 14, 2025 | CVSS8.0v3.1 | EPSS0.373% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-51767HIGH | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. CWE-287Jul 14, 2025 | CVSS7.3v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37099CRITICAL | A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. CWE-94Jul 1, 2025 | CVSS9.8v3.1 | EPSS0.639% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37098HIGH | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. CWE-22Jul 1, 2025 | CVSS7.5v3.1 | EPSS36.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37097HIGH | A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service CWE-749Jul 1, 2025 | CVSS7.5v3.1 | EPSS0.471% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37101HIGH | HPE OneView for VMware vCenter (OV4VC), Local Elevation of PrivilegeA potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). CWE-269Jun 26, 2025 | CVSS8.7v3.1 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27086HIGH | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. CWE-287Apr 21, 2025 | CVSS8.1v3.1 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27081MEDIUM | HPE NonStop OSM Service Connection Suite, Denial of Service vulnerabilityA potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service. CWE-400Apr 10, 2025 | CVSS6.8v3.1 | EPSS0.222% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-13804CRITICAL | Unauthenticated RCE in HPE Insight Cluster Management Utility CWE-287Mar 30, 2025 | CVSS9.8v3.1 | EPSS0.458% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
HPE IceWall Products, Remote Unauthorized Data ModificationA security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification. CWE-522Dec 2, 2024 | CVSS3.7v3.1 | EPSS0.272% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-51766MEDIUM | HPE NonStop DISK UTIL, Local Denial of Service vulnerabilityA potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of service (DoS) to NonStop server. It exists in all prior DISK UTIL product versions of L-series and J-series. CWE-755Nov 22, 2024 | CVSS6.5v3.1 | EPSS0.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42504MEDIUM | HPE IceWall Agent products, Cross-Site Request Forgery (CSRF)A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow. CWE-352Oct 3, 2024 | CVSS4.3v3.1 | EPSS0.152% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42400MEDIUM | Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. Aug 6, 2024 | CVSS5.3v3.1 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42399MEDIUM | Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. CWE-400Aug 6, 2024 | CVSS5.3v3.1 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-42398MEDIUM | Unauthenticated Denial-of-Service (DoS) Vulnerabilities in the Soft AP Daemon Service Accessed by the PAPI ProtocolMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point. CWE-400Aug 6, 2024 | CVSS5.3v3.1 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22444MEDIUM | A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface. CWE-79Jul 24, 2024 | CVSS6.1v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22443HIGH | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise. CWE-1321Jul 24, 2024 | CVSS7.2v3.1 | EPSS0.778% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |