Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hewlett Packard Enterprise (HPE)

First CVE: Aug 12, 2002Active for: 24 yearsTotal CVEs: 191
65.4
VTI Score
TOP TARGET

Hewlett Packard Enterprise (HPE) operates as a major infrastructure and enterprise-systems vendor whose vulnerability footprint spans a large portfolio of server hardware, storage, and management platforms deployed across data centers and enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, particularly across its ProLiant server line, where exposures center on memory-safety issues, path-traversal weaknesses, and command-injection flaws in management and firmware components. The recurring products—principally the ProLiant DL-series server platforms—and the durable weakness classes reflect the complexity of embedded firmware, BIOS interfaces, and system-management stacks that sit in privileged positions within deployed infrastructure. Defenders should treat HPE infrastructure advisories as high-priority for inventory and patching cycles, particularly where server management interfaces are network-accessible; current exploitation status and severity counts are shown alongside this summary.

FAUCET AI Generated
191
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
1.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Hewlett Packard Enterprise (HPE) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2002
23 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Self-Reporting Analysis

Of all the CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, 12.6% affect products that Hewlett Packard Enterprise (HPE) develops as a vendor.

12.6%
87.4%
Self-reported: 168 (12.6%)
Third-party: 1,168 (87.4%)

Of all the CVEs published that affect products developed by Hewlett Packard Enterprise (HPE), 88.0% are self-published by Hewlett Packard Enterprise (HPE) as a CNA.

88.0%
12.0%
Self-published: 168 (88.0%)
Other CNAs: 23 (12.0%)

Products(557 total)

Top CVEs

Signals from CVEs in this vendor scope (191 CVEs).

191 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5689CRITICAL
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (IS
May 2, 20179.899YESYES
CVE-2025-37164CRITICAL
A remote code execution issue exists in HPE OneView.
Dec 16, 20259.898YESYES
CVE-2020-7136CRITICAL
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update
Apr 30, 20209.879NOYES
CVE-2024-53675HIGH
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Nov 26, 20247.570NONO
CVE-2016-7434HIGH
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
Jan 13, 20177.565NOYES
CVE-2024-53676CRITICAL
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
Nov 27, 20249.861NONO
CVE-2024-53674HIGH
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Nov 26, 20247.547NONO
CVE-2022-37932CRITICAL
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely explo
Dec 12, 20229.844NOYES
CVE-2002-20001HIGH
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-s
Nov 11, 20217.538NONO
CVE-2025-37098HIGH
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
Jul 1, 20257.537NONO
View all 191 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products191 CVEs
30%
51%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local67 (35.1%)
Network111 (58.1%)
Unknown3 (1.6%)
Physical0 (0.0%)
Adjacent Network10 (5.2%)
Attack Complexity
Low177 (92.7%)
High11 (5.8%)
Unknown3 (1.6%)
User Interaction
None165 (86.4%)
Unknown3 (1.6%)
Required23 (12.0%)
Privileges Required
Low77 (40.3%)
High14 (7.3%)
None97 (50.8%)
Unknown3 (1.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (191 CVEs).

CISA KEV
2 CVEs
1.0% of CVEs· 99th percentile
Metasploit
2 CVEs
1.0% of CVEs· 97th percentile
Nuclei
4 CVEs
2.1% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hewlett Packard Enterprise (HPE).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hewlett Packard Enterprise (HPE) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hewlett Packard Enterprise (HPE)'s Products

View all 5 CNAs →

Top CWEs