Hewlett Packard Enterprise Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Hewlett Packard Enterprise products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
1
Beyond CISA KEV
3
Sensor Observed
0
Virtual Patch Available
0
Hewlett Packard Enterprise KEVs Added by Year
4 Hewlett Packard Enterprise KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-8961
A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution. |
Intelligent Management Center | High | Not in CISA | 12 Nov 2025 |
|
CVE-2020-7136
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard... |
Smart Update Manager (SUM) | High | Not in CISA | 31 Aug 2025 |
|
CVE-2021-29203
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management... |
HPE Edgeline Infrastructure Manager | High | Not in CISA | 11 Jun 2025 |
|
CVE-2025-37164
A remote code execution issue exists in HPE OneView. |
HPE OneView | Confirmed | In CISA | 01 Jun 2026 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-306 — Missing Authentication for Critical Function 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology