Vulnerabilities > HPE

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2022-37933 Injection vulnerability in HPE products
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers.
local
low complexity
hpe CWE-74
7.8
2023-01-05 CVE-2022-37934 Path Traversal vulnerability in multiple products
A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series.
network
low complexity
hp hpe CWE-22
7.5
2022-12-12 CVE-2022-37927 Open Redirect vulnerability in HPE Oneview Global Dashboard
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).
network
low complexity
hpe CWE-601
6.1
2022-12-12 CVE-2022-37928 Insufficient Verification of Data Authenticity vulnerability in HPE products
Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
network
low complexity
hpe CWE-345
6.5
2022-12-12 CVE-2022-37929 Improper Privilege Management vulnerability in HPE products
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
local
low complexity
hpe CWE-269
5.5
2022-12-12 CVE-2022-37930 Unspecified vulnerability in HPE products
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information.
local
low complexity
hpe
5.5
2022-12-12 CVE-2022-37932 Unspecified vulnerability in HPE products
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.
network
low complexity
hpe
critical
9.8
2022-09-20 CVE-2022-28637 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63/2.71
A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71.
local
low complexity
hpe
7.8
2022-09-20 CVE-2022-28638 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63/2.71
An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71.
local
low complexity
hpe
7.8
2022-09-20 CVE-2022-28639 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63/2.71
A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71.
low complexity
hpe
8.8