Vulnerabilities > HPE > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-12 CVE-2022-28633 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63
A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71.
local
low complexity
hpe
7.3
2022-08-12 CVE-2022-28635 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63
A potential local arbitrary code execution and a local denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71.
local
high complexity
hpe
7.4
2022-08-12 CVE-2022-28636 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63
A potential local arbitrary code execution and a local denial of service (DoS) vulnerability within an isolated process were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71.
local
high complexity
hpe
7.4
2022-06-28 CVE-2022-28621 Unspecified vulnerability in HPE Nonstop Distributed Systems Management / Software Configuration Manager T6031H03^Adp
A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP.
network
low complexity
hpe
7.5
2022-06-27 CVE-2022-28622 Use of a Broken or Risky Cryptographic Algorithm vulnerability in HPE Storeonce 3640 Firmware 4.2.3/4.3.0
A potential security vulnerability has been identified in HPE StoreOnce Software.
network
low complexity
hpe CWE-327
7.5
2022-06-24 CVE-2022-28619 Unspecified vulnerability in HPE Control Repository Manager
A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager.
local
low complexity
hpe
7.8
2022-05-09 CVE-2022-23705 Unspecified vulnerability in HPE Nimbleos
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array.
network
low complexity
hpe
7.5
2022-04-12 CVE-2021-41004 Unspecified vulnerability in HPE products
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
network
low complexity
hpe
7.5
2022-04-12 CVE-2022-23703 Unspecified vulnerability in HPE Nimbleos
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update.
network
low complexity
hpe
7.5
2022-03-02 CVE-2021-41000 Command Injection vulnerability in HPE Arubaos-Cx
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below.
network
low complexity
hpe CWE-77
8.8