hpe Vulnerabilities and Affected Products
Vulnerabilities associated with HPE System Management Homepage before v7.6.
Products
Clear product- edgeconnect_sd-wan_orchestrator14 vulnerabilities
- insight_remote_support5 vulnerabilities
- HPE System Management Homepage before v7.64 vulnerabilities
- arba_access_points_running_instantos_and_arubaos_103 vulnerabilities
- aruba_clear_pass_policy_manager3 vulnerabilities
- aruba_networking_instantos1 vulnerability
- arubaos1 vulnerability
- cray_system_management_software1 vulnerability
- HPE Business Critical Hard Drives1 vulnerability
- HPE enhanced Internet Usage Manager (eIUM)1 vulnerability
- HPE MSE Msg Gw application E-LTU1 vulnerability
- HPE NVMe Mixed Use Solid State Drives1 vulnerability
- HPE SATA Read Intensive Solid State Drives1 vulnerability
- HPE Server Enterprise Hard Drives1 vulnerability
- HPE Server SAS Hard Drives1 vulnerability
- HPE Server SATA Hard Drives1 vulnerability
- HPE Server Solid State Drives1 vulnerability
- HPE Service Pack for ProLiant1 vulnerability
- HPE Superdome Flex Server1 vulnerability
- HPE System Management Homepage (SMH)1 vulnerability
- HPE Virtual Connect SE 16Gb Fibre Channel Module for HPE Synergy1 vulnerability
- hpe_athonet_mobile_care1 vulnerability
- Integrated Lights-Out1 vulnerability
- NetBatch-Plus software1 vulnerability
- NonStop SAFEGAURD and NonStop H-series STDSEC-STANDARD SECURITY Product1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2016-4393MEDIUM | HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue. CWE-79Oct 28, 2016 | CVSS5.4v3.0 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4394MEDIUM | HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue. CWE-254Oct 28, 2016 | CVSS6.5v3.0 | EPSS2.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4396HIGH | HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue. CWE-119Oct 28, 2016 | CVSS7.5v3.0 | EPSS4.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4395HIGH | HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue. CWE-119Oct 28, 2016 | CVSS7.5v3.0 | EPSS3.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |