Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Hewlett Packard Enterprise (HPE) — Vulnerabilities & Security Advisories 616

Browse all 616 CVE security advisories affecting Hewlett Packard Enterprise (HPE). AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hewlett Packard Enterprise (HPE) operates as a critical infrastructure provider, designing and selling servers, storage, networking hardware, and associated software solutions for enterprise data centers. With 418 recorded CVEs, the company’s attack surface primarily involves its managed services and hardware management interfaces. Historically, common vulnerability classes include remote code execution (RCE) and cross-site scripting (XSS), often stemming from web-based management consoles like HPE OneView or iLO. Privilege escalation flaws also appear frequently, allowing unauthorized users to gain administrative control over managed devices. Notable incidents have included credential exposure and insecure default configurations in firmware updates, which attackers exploited to pivot into internal networks. These weaknesses highlight the risks inherent in complex, interconnected enterprise ecosystems where management planes are often targeted. The high volume of vulnerabilities underscores the necessity for rigorous patch management and strict access controls across HPE’s extensive product portfolio to mitigate potential systemic breaches.

CVE ID Title CVSS Severity Published
CVE-2025-37161 Unauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management Interface — HPE Aruba Networking 100 Series Cellular Bridge 7.5 High 2025-11-18
CVE-2025-37163 Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI — HPE Aruba Networking Management Software (Airwave) 7.2 High 2025-11-18
CVE-2025-37160 Authenticated Broken Access Control (BAC) in REST API Configuration Service — HPE Aruba Networking AOS-CX 5.3 Medium 2025-11-18
CVE-2025-37159 Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software — HPE Aruba Networking AOS-CX 5.8 Medium 2025-11-18
CVE-2025-37158 Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX — HPE Aruba Networking AOS-CX 6.7 Medium 2025-11-18
CVE-2025-37157 Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX — HPE Aruba Networkign AOS-CX 6.7 Medium 2025-11-18
CVE-2025-37156 ArubaOS-CX Platform-Level Denial-of-Service Vulnerability — HPE Aruba Networking AOS-CX 6.8 Medium 2025-11-18
CVE-2025-37155 Authenticated Privilege Escalation Allows Unauthorized Access in Network Management Interface — HPE Aruba Networking AOS-CX 7.8 High 2025-11-18
CVE-2025-37145 Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37144 Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37143 Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required) — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37142 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37141 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37140 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium 2025-10-14
CVE-2025-37139 Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot — ArubaOS (AOS) 6.0 Medium 2025-10-14
CVE-2025-37138 Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required) — ArubaOS (AOS) 6.2 Medium 2025-10-14
CVE-2025-37137 Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI) — ArubaOS (AOS) 6.5 Medium 2025-10-14
CVE-2025-37136 Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI) — ArubaOS (AOS) 6.5 Medium 2025-10-14
CVE-2025-37135 Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI) — ArubaOS (AOS) 6.5 Medium 2025-10-14
CVE-2025-37134 Authenticated Command Injection Vulnerability in the Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 7.2 High 2025-10-14
CVE-2025-37133 Authenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage. — ArubaOS (AOS) 7.2 High 2025-10-14
CVE-2025-37132 Authenticated Remote Code Execution Vulnerability in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write — ArubaOS (AOS) 7.2 High 2025-10-14
CVE-2025-37148 Kernel Panic triggered by Modified Ethernet Frames leads to Denial of Service Vulnerability — ArubaOS (AOS) 6.5 Medium 2025-10-14
CVE-2025-37147 Secure Boot Bypass allows for Compromise of Hardware Root of Trust — ArubaOS (AOS) 7.1 High 2025-10-14
CVE-2025-37146 Unauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code Execution — ArubaOS (AOS) 7.2 High 2025-10-14
CVE-2025-37149 HPE ProLiant RL300 Gen11 Server 安全漏洞 — ProLiant RL300 Gen11 Server 6.0 Medium 2025-10-14
CVE-2025-37122 Unauthenticated Reflected Cross-Site Scripting — HPE Aruba Networking ClearPass Policy Manager 6.1 Medium 2025-09-17
CVE-2025-37125 Broken access control vulnerability in Firewall Configuration Leads to Unauthorized Access to Internal Network Resources — HPE Aruba Networking EdgeConnect SD-WAN Gateway 7.5 High 2025-09-16
CVE-2025-37123 Authenticated Command Injection leads to Unauthorized Actions in CLI Interface — HPE Aruba Networking EdgeConnect SD-WAN Gateway 8.8 High 2025-09-16
CVE-2025-37124 Unauthenticated Access Vulnerability allows Transit Traffic Misrouting in SD-WAN Edge Interface — HPE Aruba Networking EdgeConnect SD-WAN Gateway 8.6 High 2025-09-16

This page lists every published CVE security advisory associated with Hewlett Packard Enterprise (HPE). Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.