Vulnerabilities > HPE > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-37929 Improper Privilege Management vulnerability in HPE products
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.
local
low complexity
hpe CWE-269
5.5
2022-12-12 CVE-2022-37930 Unspecified vulnerability in HPE products
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information.
local
low complexity
hpe
5.5
2022-08-12 CVE-2022-28626 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71.
local
low complexity
hpe
6.7
2022-08-12 CVE-2022-28634 Unspecified vulnerability in HPE Integrated Lights-Out 5 Firmware 2.63
A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71.
local
low complexity
hpe
6.7
2022-07-08 CVE-2022-28624 Cross-site Scripting vulnerability in HPE products
A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products.
network
low complexity
hpe CWE-79
4.8
2022-04-12 CVE-2021-41005 Unspecified vulnerability in HPE products
A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.
network
low complexity
hpe
6.5
2022-04-12 CVE-2022-23702 Unspecified vulnerability in HPE products
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers.
local
low complexity
hpe
6.7
2022-03-02 CVE-2021-41003 Unspecified vulnerability in HPE Arubaos-Cx
Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): AOS-CX 10.06.xxxx: 10.06.0170 and below, AOS-CX 10.07.xxxx: 10.07.0050 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.09.xxxx: 10.09.0002 and below.
network
low complexity
hpe
6.1
2022-02-24 CVE-2021-29216 Cross-site Scripting vulnerability in HPE Oneview Global Dashboard
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5.
network
low complexity
hpe CWE-79
6.1
2022-02-24 CVE-2021-29217 Open Redirect vulnerability in HPE Oneview Global Dashboard
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5.
network
low complexity
hpe CWE-601
6.1