Oneview

Vendor:

First CVE: May 8, 2014 · Active for 12 years

22
Total CVEs
More Total CVEs than 94% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Oneview over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2014
12 years ago
Most Recent CVE
Jan 23, 2024
913 days ago

CVE Severity & Scoring

Oneview22 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local12 (54.5%)
Network9 (40.9%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High0 (0.0%)
Unknown1 (4.5%)
User Interaction
None18 (81.8%)
Unknown1 (4.5%)
Required3 (13.6%)
Privileges Required
Low12 (54.5%)
High0 (0.0%)
None9 (40.9%)
Unknown1 (4.5%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability i
May 17, 20229.831NONO
A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE
May 17, 20229.831NONO
A remote authentication bypass issue exists in a OneView API.
Sep 7, 20239.830NONO
There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy
Nov 6, 20208.828NONO
A remote authentication bypass issue exists in some OneView APIs.
Sep 14, 20239.827NONO
A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in
Apr 4, 20227.825NONO
An HPE OneView appliance dump may expose SAN switch administrative credentials
Apr 25, 20237.824NONO
A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerab
Apr 4, 20227.524NONO
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
Apr 25, 20237.123NONO
Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors.
May 8, 20146.523NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Oneview

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.418.82.0%00
5.318.82.0%00
5.20.0118.82.0%00
5.218.82.0%00
5.00.0218.82.0%00
5.00.0118.82.0%00
5.018.82.0%00
1.0116.52.0%00
1.016.52.0%00