HPE vulnerabilities
4 CVEs tracked
HPE appears in recent reporting within the context of both legacy hardware and modern networking products. The main incident involves the decades-old IPMI vulnerability CVE-2013-4786, which still affects thousands of BMC systems by disclosing password hashes before authentication. Concurrently, critical authentication bypass flaws (CVE-2026-63455, CVE-2026-63456) have been found in the REST API of HPE Networking SD-WAN Orchestrator, and a denial-of-service vulnerability (CVE-2026-63457) impacts iLO 6. Defenders should apply the iLO 6 firmware update and ensure no BMC interfaces are exposed to the internet.
Azərbaycanca: HPE son hesabatlarda həm miras qalmış avadanlıq, həm də yeni şəbəkə məhsulları kontekstində görünür. Əsas hadisə 2013-cü ilə aid IPMI zəifliyinin (CVE-2013-4786) hələ də minlərlə BMC (baseboard management controller) sistemini təsirləndirərək parol heşlərinin ifşasına səbəb olmasıdır. Paralel olaraq, HPE Networking SD-WAN Orchestrator-un REST API-sində autentifikasiyadan yan keçməyə imkan verən kritik zəifliklər (CVE-2026-63455, CVE-2026-63456) aşkarlanıb. Müdafiəçilər xüsusilə iLO 6 (CVE-2026-63457) üçün buraxılmış proqram təminatı yeniləmələrini tətbiq etməli və BMC interfeyslərinin internetə açıq olmadığına əmin olmalıdır.
This vendor's CVEs4
This hub is built from skopnix's own reporting on HPE: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.