Known Vulnerabilities for products from Hpe
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Hpe".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Hpe can be found at device.report : Hpe
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63457 json | A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-63454 json | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attac... | Not Provided | 2026-07-21 | 2026-08-11 |
| CVE-2026-63453 json | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabiliti... | Not Provided | 2026-07-21 | 2026-08-11 |
| CVE-2026-44880 json | A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabi... | Not Provided | 2026-07-21 | 2026-08-11 |
| CVE-2026-23818 json | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem tha... | Not Provided | 2026-04-07 | 2026-04-14 |
| CVE-2026-23817 json | A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker to re... | Not Provided | 2026-03-11 | 2026-05-13 |
| CVE-2026-23816 json | A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbi... | Not Provided | 2026-03-11 | 2026-08-11 |
| CVE-2026-23815 json | A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privil... | Not Provided | 2026-03-11 | 2026-08-11 |
| CVE-2026-23814 json | A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote at... | Not Provided | 2026-03-11 | 2026-08-11 |
| CVE-2026-23813 json | A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an ... | Not Provided | 2026-03-11 | 2026-08-11 |
| CVE-2026-23600 json | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS). | Not Provided | 2026-03-02 | 2026-08-10 |
| CVE-2023-39268 json | A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving speciall... | 9.8 - CRITICAL | 2023-08-29 | 2023-09-11 |
| CVE-2023-39267 json | An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful explo... | 6.5 - MEDIUM | 2023-08-29 | 2023-09-11 |
| CVE-2023-39266 json | A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a st... | 6.1 - MEDIUM | 2023-08-29 | 2023-09-11 |
| CVE-2023-30912 json | A remote code execution issue exists in HPE OneView. | 9.8 - CRITICAL | 2023-10-25 | 2023-10-31 |
| CVE-2023-30911 json | HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service. | 7.5 - HIGH | 2023-10-18 | 2023-10-25 |
| CVE-2023-30910 json | HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP reque... | 5.4 - MEDIUM | 2023-10-09 | 2023-10-13 |
| CVE-2023-30906 json | The vulnerability could be locally exploited to allow escalation of privilege. | 7.8 - HIGH | 2023-07-18 | 2023-07-27 |
| CVE-2023-30905 json | The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privi... | 7.8 - HIGH | 2023-06-16 | 2023-06-29 |
| CVE-2023-30904 json | A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information. | 5.5 - MEDIUM | 2023-06-16 | 2023-06-29 |
Known software with vulnerabilities from Hpe
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Hpe | 3500 | - |
| Operating System | Hpe | 3500 Firmware | k.16.02.0032 |
| Hardware | Hpe | 3500 Yl | - |
| Operating System | Hpe | 3500 Yl Firmware | k.16.02.0032 |
| Hardware | Hpe | 6200 Yl | - |
| Operating System | Hpe | 6200 Yl Firmware | k.15.18.0024 |
| Hardware | Hpe | 8200 Zl | - |
| Operating System | Hpe | 8200 Zl Firmware | k.15.18.0024 |
| Hardware | Hpe | Apollo 2000 Gen10 Plus System | - |
| Hardware | Hpe | Apollo 4200 Gen10 Server | - |
| Operating System | Hpe | Apollo 4200 Gen10 Server Firmware | - |
| Hardware | Hpe | Apollo 4200 Gen9 Server | - |
| Operating System | Hpe | Apollo 4200 Gen9 Server Firmware | - |
| Hardware | Hpe | Apollo 4510 Gen10 System | - |
| Hardware | Hpe | Apollo 4520 Chassis | - |
| Hardware | Hpe | Apollo 6500 Gen10 System | - |
| Application | Hpe | Aruba Airwave | 6.3.1 |
| Hardware | Hpe | Cloudline Cl2100 Gen10 Server | - |
| Hardware | Hpe | Cloudline Cl2200 Gen10 Server | - |
| Hardware | Hpe | Cloudline Cl2600 Gen10 Server | - |