Vulnerability index

Browse CVEs

177 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Slingshot Firmware CRITICAL 9.8
CVE-2022-28620

A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers…

Fix: 1.7.2+
Fix from $2,300 2022-06-24
Control Repository Manager HIGH 7.8
CVE-2022-28619

A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow loca…

Fix: 7.6.14.0+
Fix from $1,950 2022-06-24
Nimbleos CRITICAL 9.8
CVE-2022-28618

A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE…

Fix: 5.0.10.100 / 5.2.1.500+
Fix from $2,300 2022-05-20
Nimbleos HIGH 7.5
CVE-2022-23705

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage S…

Fix: 5.0.10.100 / 5.2.1.500+
Fix from $1,950 2022-05-09
Nimbleos HIGH 7.5
CVE-2022-23703

A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Se…

Fix: 5.0.10.100 / 5.2.1.500+
Fix from $1,950 2022-04-12
Superdome Flex Server Firmware MEDIUM 6.7
CVE-2022-23702

A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally explo…

Fix: 1.20.204 / 3.50.58+
Fix from $1,600 2022-04-12
Aruba Instant On 1930 8g 2sfp Firmware HIGH 7.5
CVE-2021-41004

A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

Fix: 1.0.7.0+
Fix from $1,950 2022-04-12
Aruba Instant On 1930 8g 2sfp Firmware MEDIUM 6.5
CVE-2021-41005

A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

Fix: 1.0.7.0+
Fix from $1,600 2022-04-12
Arubaos Cx HIGH 8.8
CVE-2021-41000

Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Ar…

Fix: after 10.07.0020
Fix from $1,950 2022-03-02
Arubaos Cx HIGH 8.8
CVE-2021-41001

An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aru…

Fix: after 10.09.0002
Fix from $1,950 2022-03-02
Arubaos Cx HIGH 8.1
CVE-2021-41002

Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Ar…

Fix: after 10.09.0002
Fix from $1,950 2022-03-02
Arubaos Cx MEDIUM 6.1
CVE-2021-41003

Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Sw…

Fix: after 10.09.0002
Fix from $1,600 2022-03-02
Oneview Global Dashboard MEDIUM 6.1
CVE-2021-29216

A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software upda…

Fix: 2.5+
Fix from $1,600 2022-02-24
Oneview Global Dashboard MEDIUM 6.1
CVE-2021-29217

A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to…

Fix: 2.5+
Fix from $1,600 2022-02-24
Integrated Lights Out MEDIUM 5.3
CVE-2022-23701

A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior…

Fix: 2.60+
Fix from $1,600 2022-02-24
Flexnetwork 5130 Jg932a Firmware HIGH 7.8
CVE-2021-29219

A potential local buffer overflow vulnerability has been identified in HPE FlexNetwork 5130 EL Switch Series version: Prior to 5130_EI_7.10.R3507P02.…

Fix: 5130_ei_7.10.r3507p02+
Fix from $1,950 2022-02-04
Agentless Management MEDIUM 6.7
CVE-2021-29218

A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows version(s): Prior to 1.44.0.0…

Fix: 1.44.0.0 / 10.96.0.0+
Fix from $1,600 2022-02-04
Tez CRITICAL 9.8
CVE-2021-29215

A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component w…

Fix: 0.9.201907090334-1.noarch+
Fix from $2,300 2022-01-18
Proliant Microserver Gen10 Plus Firmware MEDIUM 6.7
CVE-2021-29213

A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProLiant ML30 Gen10, and HPE ProL…

Fix: 2.52+
Fix from $1,600 2021-11-01
Superdome Flex Firmware MEDIUM 6.1
CVE-2021-26589

A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Si…

Fix: 3.40.106+
Fix from $1,600 2021-10-19
3par Os CRITICAL 9.8
CVE-2021-26588

A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An una…

Fix: after 9.4.0
Fix from $2,300 2021-10-11
Storeonce 5200 Firmware MEDIUM 6.5
CVE-2021-26587

A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited…

Fix: after 4.2.3
Fix from $1,600 2021-09-27
Backbox H4.09 Firmware HIGH 8.1
CVE-2021-33895

ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox U…

Mitigation only
Fix from $1,950 2021-06-25
Oneview Global Dashboard MEDIUM 5.5
CVE-2021-26585

A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged infor…

Mitigation only
Fix from $1,600 2021-06-24
Superdome Flex Server Firmware MEDIUM 6.5
CVE-2021-26581

A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hun…

Fix: 3.30.142+
Fix from $1,600 2021-04-01
Integrated Lights Out Amplifier MEDIUM 6.1
CVE-2021-26580

A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site S…

Fix: 1.95+
Fix from $1,600 2021-04-01
Unified Data Management MEDIUM 5.5
CVE-2021-26579

A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded …

Mitigation only
Fix from $1,600 2021-03-30
Network Orchestrator HIGH 7.5
CVE-2021-26578

A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remote…

Fix: 2.5+
Fix from $1,950 2021-03-22
Web Viewpoint HIGH 8.8
CVE-2021-3191

Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows Remote Unauthorized Access for T0320L01^ABY and T0320L01^ACD, T0952L01^AA…

Fix: after 19.08.00
Fix from $1,950 2021-02-09
Web Viewpoint MEDIUM 5.9
CVE-2021-22267

Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP through T0320L01^ABZ, T0952L01^AA…

Fix: after 19.08.00
Fix from $1,600 2021-02-09