Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Hewlett Packard Enterprise (HPE) — Vulnerabilities & Security Advisories 616

Browse all 616 CVE security advisories affecting Hewlett Packard Enterprise (HPE). AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hewlett Packard Enterprise (HPE) operates as a critical infrastructure provider, designing and selling servers, storage, networking hardware, and associated software solutions for enterprise data centers. With 418 recorded CVEs, the company’s attack surface primarily involves its managed services and hardware management interfaces. Historically, common vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from web-based management consoles like HPE OneView or iLO. Privilege escalation flaws also appear frequently, allowing unauthorized users to gain administrative control over managed devices. Notable incidents have included credential exposure and insecure default configurations in firmware updates, which attackers exploited to pivot into internal networks. These weaknesses highlight the risks inherent in complex, interconnected enterprise ecosystems where management planes are often targeted. The high volume of vulnerabilities underscores the necessity for rigorous patch management and strict access controls across HPE’s extensive product portfolio to mitigate potential systemic breaches.

CVE ID Title CVSS Severity Published
CVE-2026-73763 Unauthenticated Remote Command Execution in Management Component — AOS-CX 7.1 High 2026-09-01
CVE-2026-73762 Authorization Bypass in the API Endpoint of AOS-CX Leads to Unauthorized Access — AOS-CX 6.6 Medium 2026-09-01
CVE-2026-73761 Unauthenticated Out-of-Bounds Read Vulnerability leads to Information Disclosure in AOS-CX — AOS-CX 6.5 Medium 2026-09-01
CVE-2026-73760 Authenticated Path Traversal Vulnerability Leads to Remote Unauthorized Access to Files in AOS-CX — AOS-CX 6.5 Medium 2026-09-01
CVE-2026-73759 Unauthenticated Denial-of-Service Vulnerabilities in AOS-CX — AOS-CX 6.5 Medium 2026-09-01
CVE-2026-73758 Authenticated Privilege Escalation Vulnerability via Broken Access Control in AOS-CX — AOS-CX 6.5 Medium 2026-09-01
CVE-2026-73757 Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure in AOS-CX — AOS-CX 6.4 Medium 2026-09-01
CVE-2026-73756 Unauthenticated Sensitive Information Disclosure via Man-in-the-Middle in AOS-CX via API Endpoint — AOS-CX 5.9 Medium 2026-09-01
CVE-2026-73755 Privilege Escalation via Unauthorized Access to Sensitive Session Information — AOS-CX 5.7 Medium 2026-09-01
CVE-2026-73754 Authenticated Denial-of-Service Vulnerabilities in the Command Line Interface of AOS-CX — AOS-CX 5.3 Medium 2026-09-01
CVE-2026-73753 Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface — AOS-CX 8.8 High 2026-09-01
CVE-2026-73752 Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX — AOS-CX 8.8 High 2026-09-01
CVE-2026-73751 Authenticated Remote Command Injection in AOS-CX Web-based Management Interface — AOS-CX 8.8 High 2026-09-01
CVE-2026-73750 Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution — AOS-CX 8.8 High 2026-09-01
CVE-2026-73749 Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX — AOS-CX 9.8 Critical 2026-09-01
CVE-2026-76658 Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon — Fabric Composer 10.0 Critical 2026-09-01
CVE-2026-76657 Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access — Fabric Composer 10.0 Critical 2026-09-01
CVE-2026-73748 Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer — Fabric Composer 2.2 Low 2026-09-01
CVE-2026-73747 Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer — Fabric Composer 2.5 Low 2026-09-01
CVE-2026-73746 Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer API — Fabric Composer 3.1 Low 2026-09-01
CVE-2026-73744 Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface — Fabric Composer 3.5 Low 2026-09-01
CVE-2026-73743 Unauthenticated Information Disclosure Leading to Data Exposure in HPE Networking Fabric Composer — Fabric Composer 3.7 Low 2026-09-01
CVE-2026-73742 Improper Client Address Validation allows Request Attribution Spoofing in Fabric Composer API Endpoint — Fabric Composer 4.3 Medium 2026-09-01
CVE-2026-73741 Authenticated Limited File Read allows Data Exposure in HPE Networking Fabric Composer API — Fabric Composer 4.3 Medium 2026-09-01
CVE-2026-73740 Local Privilege Escalation in HPE Networking Fabric Composer — Fabric Composer 4.4 Medium 2026-09-01
CVE-2026-73739 Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer API — Fabric Composer 4.4 Medium 2026-09-01
CVE-2026-73738 Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer — Fabric Composer 4.7 Medium 2026-09-01
CVE-2026-73737 Unauthenticated Path Traversal in HPE Networking Fabric Composer API Endpoint Allows Unauthorized File Modification — Fabric Composer 4.8 Medium 2026-09-01
CVE-2026-73736 Unauthenticated Limited Information Disclosure leads to Data Exposure in HPE Networking Fabric Composer — Fabric Composer 5.3 Medium 2026-09-01
CVE-2026-73735 Authenticated Access Control Vulnerabilities allow Information Disclosure in HPE Networking Fabric Composer API — Fabric Composer 5.4 Medium 2026-09-01

This page lists every published CVE security advisory associated with Hewlett Packard Enterprise (HPE). Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.