Oneview
Vendor:
First CVE: May 8, 2014 · Active for 12 years
22
Total CVEs
More Total CVEs than 94% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Oneview over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 8, 2014
12 years ago
Most Recent CVE
Jan 23, 2024
913 days ago
CVE Severity & Scoring
Oneview22 CVEs
50%
32%
18%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local12 (54.5%)
Network9 (40.9%)
Unknown1 (4.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (95.5%)
High0 (0.0%)
Unknown1 (4.5%)
User Interaction
None18 (81.8%)
Unknown1 (4.5%)
Required3 (13.6%)
Privileges Required
Low12 (54.5%)
High0 (0.0%)
None9 (40.9%)
Unknown1 (4.5%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28616CRITICAL A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability i | May 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-28617CRITICAL A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE | May 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-30908CRITICAL A remote authentication bypass issue exists in a OneView API.
| Sep 7, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-7198HIGH There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy | Nov 6, 2020 | 8.8 | 28 | NO | NO |
CVE-2023-30909CRITICAL A remote authentication bypass issue exists in some
OneView APIs.
| Sep 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-23699HIGH A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in | Apr 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2023-28088HIGH An HPE OneView appliance dump may expose SAN switch administrative credentials | Apr 25, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-23698HIGH A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerab | Apr 4, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-28089HIGH An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules | Apr 25, 2023 | 7.1 | 23 | NO | NO |
CVE-2014-2602MEDIUM Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors. | May 8, 2014 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Oneview
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.4 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.3 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.20.01 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.2 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.00.02 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.00.01 | 1 | 8.8 | 2.0% | 0 | 0 |
| 5.0 | 1 | 8.8 | 2.0% | 0 | 0 |
| 1.01 | 1 | 6.5 | 2.0% | 0 | 0 |
| 1.0 | 1 | 6.5 | 2.0% | 0 | 0 |