CVE-2025-37098
largeUnauthenticated Path Traversal File Read in HPE Insight Remote Support
CVE-2025-37098 is a path traversal (CWE-22) flaw in HPE Insight Remote Support (IRS), the on-premises appliance HPE provides for remote monitoring and support of server environments; all versions prior to 7.15.0.646 are affected. An attacker with network reachability to the IRS service sends a crafted request containing a malicious path, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no authentication, privileges, or user interaction are required. Successful exploitation allows reading arbitrary files on the host with high confidentiality impact but no integrity or availability impact, potentially exposing sensitive configuration or credential material. Any organization running HPE IRS before 7.15.0.646 is affected, typically in enterprise datacenter and management networks. Exploitation has not been confirmed in the wild, the flaw is not on CISA's KEV, and no public proof-of-concept is known, but EPSS assigns a 37.2% probability of exploitation within 30 days (98th percentile), indicating elevated near-term risk.
What to do: Upgrade to HPE Insight Remote Support 7.15.0.646 or later per HPE's advisory. Until patched, restrict network access to the IRS server (segment it into management networks and firewall the service), since the flaw requires no credentials or user interaction. Given the high EPSS score, prioritize patching any internet-reachable instances and monitor for updates from HPE.
| HPE Insight Remote Support | all versions prior to 7.15.0.646 (fixed in 7.15.0.646) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
- Vendors
- hpe
- Products
- insight remote support
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.