Vulnerability index

Browse CVEs

177 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kvm Ip Console Switch G2 Firmware HIGH 8.8
CVE-2020-24628

A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

Fix: 2.8.3+
Fix from $1,950 2020-10-02
Kvm Ip Console Switch G2 Firmware MEDIUM 5.4
CVE-2020-24627

A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

Fix: 2.8.3+
Fix from $1,600 2020-10-02
Utility Computing Service Meter CRITICAL 9.8
CVE-2020-24626

Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Use (PPU) …

Mitigation only
Fix from $2,300 2020-09-23
Utility Computing Service Meter HIGH 7.5
CVE-2020-24624

Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Co…

Mitigation only
Fix from $1,950 2020-09-23
Utility Computing Service Meter HIGH 7.5
CVE-2020-24625

Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Comp…

Mitigation only
Fix from $1,950 2020-09-23
Universal Api Framework MEDIUM 6.5
CVE-2020-24623

A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exp…

Fix: 2.5.2+
Fix from $1,600 2020-09-18
Smartstart Scripting Toolkit MEDIUM 6.7
CVE-2020-7205

A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vul…

Fix: 1.72 / 2.81+
Fix from $1,600 2020-07-30
Nimbleos HIGH 8.8
CVE-2020-7138

Potential remote code execution security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker …

Fix: after 5.1.4.100
Fix from $1,950 2020-05-19
Nimbleos HIGH 8.1
CVE-2020-7139

Potential remote access security vulnerabilities have been identified with HPE Nimble Storage systems that could be exploited by an attacker to acces…

Fix: after 5.1.4.100
Fix from $1,950 2020-05-19
Superdome Flex Server Firmware MEDIUM 6.7
CVE-2020-7137

A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Flex Server version 3.25.46 or l…

Fix: 3.25.46+
Fix from $1,600 2020-05-19
Smart Update Manager CRITICAL 9.8
CVE-2020-7136EPSS 80%

A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise …

Fix: 8.5.6+
Fix from $2,300 2020-04-30
Msa 1040 Firmware CRITICAL 9.8
CVE-2019-12002

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE M…

Mitigation only
Fix from $2,300 2020-04-17
Msa 1040 Firmware MEDIUM 6.4
CVE-2019-12001

A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE M…

Mitigation only
Fix from $1,600 2020-04-17
Opencall Media Platform MEDIUM 6.9
CVE-2019-11999

Potential security vulnerabilities have been identified in HPE OpenCall Media Platform (OCMP) resulting in remote arbitrary file download and cross s…

Fix: 4.4.8 / 4.5.2+
Fix from $1,600 2020-04-16
Superdome Flex Server Firmware MEDIUM 5.5
CVE-2019-11998

HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerabilit…

Fix: 3.20.186+
Fix from $1,600 2020-01-16
Nimbleos CRITICAL 9.8
CVE-2019-11996

Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities coul…

Fix: after 5.1.2.0
Fix from $2,300 2019-11-07
Smart Update Manager CRITICAL 9.8
CVE-2019-11988

A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

Fix: 8.3.5+
Fix from $2,300 2019-06-05
Smart Update Manager HIGH 7.8
CVE-2019-11987

A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege.

Fix: 8.4+
Fix from $1,950 2019-06-05
Service Governance Framework MEDIUM 5.9
CVE-2018-7110

A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condi…

Mitigation only
Fix from $1,600 2018-10-17
Device Entitlement Gateway HIGH 8.8
CVE-2018-7107

A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be re…

Mitigation only
Fix from $1,950 2018-09-27
Storageworks Xp7 Automation Director MEDIUM 5.9
CVE-2018-7108

HPE StorageWorks XP7 Automation Director (AutoDir) version 8.5.2-02 to earlier than 8.6.1-00 has a local and remote authentication bypass vulnerabili…

Fix: 8.6.1-00+
Fix from $1,600 2018-09-27
3par Service Provider MEDIUM 5.5
CVE-2018-7094

A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to a…

Mitigation only
Fix from $1,600 2018-08-14
Arubaos HIGH 7.5
CVE-2017-9003

Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time an…

Mitigation only
Fix from $1,950 2018-08-06
Proliant Ml10 Gen9 Server Firmware CRITICAL 9.8
CVE-2017-5689 KEVEPSS 92%

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and I…

Fix: 6.2.61.3535 / 9.1.41.3024+
Fix from $2,300 2017-05-02
Project And Portfolio Management Center HIGH 8.8
CVE-2016-4370

HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or o…

Mitigation only
Fix from $1,950 2016-06-09
Smart Update Manager HIGH 7.2
CVE-2014-2608

Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users t…

Fix: 6.4.1+
Fix from $1,950 2014-12-10
Compaq Wl310 Firmware MEDIUM 6.4
CVE-2002-0812

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default S…

Mitigation only
Fix from $1,600 2002-08-12