Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Hewlett Packard Enterprise (HPE) — Vulnerabilities & Security Advisories 418

Browse all 418 CVE security advisories affecting Hewlett Packard Enterprise (HPE). AI-powered Chinese analysis, POCs, and references for each vulnerability.

Top products by Hewlett Packard Enterprise (HPE):Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba CentralAruba ClearPass Policy ManagerArubaOS (AOS)EdgeConnect SD-WAN OrchestratorAruba EdgeConnect Enterprise SoftwareAOS-8 Instant and AOS-10 APAruba Access Points running InstantOS and ArubaOS 10Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series; Aruba EdgeConnect Enterprise Orchestration SoftwareHPE OneViewHPE Aruba Networking ClearPass Policy ManagerAOS-CXHPE Aruba Networking EdgeConnect SD-WAN GatewayHPE Athonet CoreHPE StoreOnce SoftwareArubaOS Wi-Fi Controllers and Campus/Remote Access PointsHPE 3PAR Service ProcessorHPE Aruba Networking AOSHPE 3PAR StoreServ Management and Core Software MediaHPE Aruba Networking Access Points, Instant AOS-8, and AOS-10Aruba OSHPE Aruba Networking Fabric Composer (AFC)HPE Aruba Networking AOS-CXHPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10HPE Aruba Networking Private 5G CoreHPE Aruba Networking EdgeConnect SD-WANHPE Insight Remote SupportClearPass Policy Manager (CPPM)HPE Aruba Networking Wireless Operating Systems (AOS-8 & AOS-10)HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8)
CVE IDTitleCVSSSeverityPublished
CVE-2025-37175 Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37174 Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37173 Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI) — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37172 Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37171 Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37170 Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37169 Stack Overflow Vulnerability in AOS-10 Web-Based Management Interface — ArubaOS (AOS) 7.2 High2026-01-13
CVE-2025-37168 Unauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating System — ArubaOS (AOS) 8.2 High2026-01-13
CVE-2025-37166 Unexpected shutdown in HPE Instant On Access Points after processing specific packets — Instant On 7.5 High2026-01-13
CVE-2025-37165 Exposure of VLAN information in unintended network interfaces — Instant On 7.5 High2026-01-13
CVE-2025-37164 HPE OneView 安全漏洞 — HPE OneView 10.0 Critical2025-12-16
CVE-2025-37162 Authenticated Command Injection Vulnerability Leading to Arbitrary Remote Command Execution — HPE Aruba Networking 100 Series Cellular Bridge 6.5 Medium2025-11-18
CVE-2025-37161 Unauthenticated Remote Denial-of-Service (DoS) Vulnerability in Web Management Interface — HPE Aruba Networking 100 Series Cellular Bridge 7.5 High2025-11-18
CVE-2025-37163 Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI — HPE Aruba Networking Management Software (Airwave) 7.2 High2025-11-18
CVE-2025-37160 Authenticated Broken Access Control (BAC) in REST API Configuration Service — HPE Aruba Networking AOS-CX 5.3 Medium2025-11-18
CVE-2025-37159 Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software — HPE Aruba Networking AOS-CX 5.8 Medium2025-11-18
CVE-2025-37158 Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX — HPE Aruba Networking AOS-CX 6.7 Medium2025-11-18
CVE-2025-37157 Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX — HPE Aruba Networkign AOS-CX 6.7 Medium2025-11-18
CVE-2025-37156 ArubaOS-CX Platform-Level Denial-of-Service Vulnerability — HPE Aruba Networking AOS-CX 6.8 Medium2025-11-18
CVE-2025-37155 Authenticated Privilege Escalation Allows Unauthorized Access in Network Management Interface — HPE Aruba Networking AOS-CX 7.8 High2025-11-18
CVE-2025-37145 Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37144 Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37143 Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required) — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37142 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37141 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37140 Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface — ArubaOS (AOS) 4.9 Medium2025-10-14
CVE-2025-37139 Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot — ArubaOS (AOS) 6.0 Medium2025-10-14
CVE-2025-37138 Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required) — ArubaOS (AOS) 6.2 Medium2025-10-14
CVE-2025-37137 Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI) — ArubaOS (AOS) 6.5 Medium2025-10-14
CVE-2025-37136 Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI) — ArubaOS (AOS) 6.5 Medium2025-10-14

This page lists every published CVE security advisory associated with Hewlett Packard Enterprise (HPE). Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.