Hewlett Packard Enterprise Hpe Oneview vulnerabilities

23 known vulnerabilities affecting hewlett_packard_enterprise/hpe_oneview.

Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH6MEDIUM11

Vulnerabilities

Page 1 of 2
CVE-2025-37164CRITICALCVSS 9.8KEVPoCfixed in 11.002025-12-16
CVE-2025-37164 [CRITICAL] CWE-94 CVE-2025-37164: A remote code execution issue exists in HPE OneView. A remote code execution issue exists in HPE OneView.
cvelistv5nvd
CVE-2024-42508MEDIUMCVSS 5.5fixed in 9.202024-10-18
CVE-2024-42508 [MEDIUM] CWE-200 CVE-2024-42508: This vulnerability could be exploited, leading to unauthorized disclosure of information to authenti This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
cvelistv5nvd
CVE-2023-50274HIGHCVSS 7.8fixed in 8.702024-01-23
CVE-2023-50274 [HIGH] CWE-77 CVE-2023-50274: HPE OneView may allow command injection with local privilege escalation. HPE OneView may allow command injection with local privilege escalation.
cvelistv5nvd
CVE-2023-50275HIGHCVSS 7.5fixed in 8.702024-01-23
CVE-2023-50275 [HIGH] CWE-287 CVE-2023-50275: HPE OneView may allow clusterService Authentication Bypass resulting in denial of service. HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
cvelistv5nvd
CVE-2023-6573MEDIUMCVSS 5.5fixed in 8.702024-01-23
CVE-2023-6573 [MEDIUM] CWE-522 CVE-2023-6573: HPE OneView may have a missing passphrase during restore. HPE OneView may have a missing passphrase during restore.
cvelistv5nvd
CVE-2023-30912CRITICALCVSS 9.8fixed in 8.60.002023-10-25
CVE-2023-30912 [CRITICAL] CWE-94 CVE-2023-30912: A remote code execution issue exists in HPE OneView. A remote code execution issue exists in HPE OneView.
cvelistv5nvd
CVE-2023-30909CRITICALCVSS 9.8fixed in 8.30.012023-09-14
CVE-2023-30909 [CRITICAL] CWE-294 CVE-2023-30909: A remote authentication bypass issue exists in some OneView APIs. A remote authentication bypass issue exists in some OneView APIs.
cvelistv5nvd
CVE-2023-30908CRITICALCVSS 9.8fixed in 8.5fixed in 6.60.05 LTS2023-09-07
CVE-2023-30908 [CRITICAL] CVE-2023-30908: A remote authentication bypass issue exists in a OneView API. A remote authentication bypass issue exists in a OneView API.
cvelistv5nvd
CVE-2023-28089HIGHCVSS 7.1fixed in 8.2fixed in 6.60.04 LTS2023-04-25
CVE-2023-28089 [HIGH] CWE-522 CVE-2023-28089: An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
cvelistv5nvd
CVE-2023-28088HIGHCVSS 7.8fixed in 8.2fixed in 6.60.042023-04-25
CVE-2023-28088 [HIGH] CWE-522 CVE-2023-28088: An HPE OneView appliance dump may expose SAN switch administrative credentials An HPE OneView appliance dump may expose SAN switch administrative credentials
cvelistv5nvd
CVE-2023-28084MEDIUMCVSS 5.5≤ 8.2fixed in 6.60.042023-04-25
CVE-2023-28084 [MEDIUM] CWE-522 CVE-2023-28084: HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
cvelistv5nvd
CVE-2023-28090MEDIUMCVSS 5.5fixed in 8.2fixed in 6.60.04 LTS2023-04-25
CVE-2023-28090 [MEDIUM] CWE-522 CVE-2023-28090: An HPE OneView appliance dump may expose SNMPv3 read credentials An HPE OneView appliance dump may expose SNMPv3 read credentials
cvelistv5nvd
CVE-2023-28086MEDIUMCVSS 5.5fixed in 8.2fixed in 6.60.04 LTS2023-04-25
CVE-2023-28086 [MEDIUM] CWE-522 CVE-2023-28086: An HPE OneView appliance dump may expose proxy credential settings An HPE OneView appliance dump may expose proxy credential settings
cvelistv5nvd
CVE-2023-28087MEDIUMCVSS 5.5fixed in 8.2fixed in 6.60.04 LTS2023-04-25
CVE-2023-28087 [MEDIUM] CWE-522 CVE-2023-28087: An HPE OneView appliance dump may expose OneView user accounts An HPE OneView appliance dump may expose OneView user accounts
cvelistv5nvd
CVE-2023-28091MEDIUMCVSS 5.5≥ 7.0, ≤ 8.12023-04-14
CVE-2023-28091 [MEDIUM] CVE-2023-28091: HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in a HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump
cvelistv5nvd
CVE-2022-28625MEDIUMCVSS 5.5vPrior to 7.0 or 6.60.012022-08-31
CVE-2022-28625 [MEDIUM] CVE-2022-28625: A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7 A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user could locally exploit this vulnerability to disclose sensitive information resulting in a complete loss of confidentiality, integrity, and availability. To exploit this vulnerability, HPE OneView must b
cvelistv5
CVE-2022-28617CRITICALCVSS 9.8vPrior to 7.02022-05-17
CVE-2022-28617 [CRITICAL] CVE-2022-28617: A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7 A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
cvelistv5
CVE-2022-28616CRITICALCVSS 9.8vPrior to 7.02022-05-17
CVE-2022-28616 [CRITICAL] CVE-2022-28616: A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7 A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
cvelistv5
CVE-2022-23706MEDIUMCVSS 6.1vPrior to 7.02022-05-17
CVE-2022-23706 [MEDIUM] CVE-2022-23706: A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7 A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.
cvelistv5
CVE-2022-23699HIGHCVSS 7.8vPrior to 6.62022-04-04
CVE-2022-23699 [HIGH] CVE-2022-23699: A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6 A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.
cvelistv5