ZeroHour

CVE-2025-37098

large

Unauthenticated Path Traversal File Read in HPE Insight Remote Support

CVSS 3.1
7.5 high
EPSS
37%p98
Published
()
Modified
AI analysis

CVE-2025-37098 is a path traversal (CWE-22) flaw in HPE Insight Remote Support (IRS), the on-premises appliance HPE provides for remote monitoring and support of server environments; all versions prior to 7.15.0.646 are affected. An attacker with network reachability to the IRS service sends a crafted request containing a malicious path, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that no authentication, privileges, or user interaction are required. Successful exploitation allows reading arbitrary files on the host with high confidentiality impact but no integrity or availability impact, potentially exposing sensitive configuration or credential material. Any organization running HPE IRS before 7.15.0.646 is affected, typically in enterprise datacenter and management networks. Exploitation has not been confirmed in the wild, the flaw is not on CISA's KEV, and no public proof-of-concept is known, but EPSS assigns a 37.2% probability of exploitation within 30 days (98th percentile), indicating elevated near-term risk.

What to do: Upgrade to HPE Insight Remote Support 7.15.0.646 or later per HPE's advisory. Until patched, restrict network access to the IRS server (segment it into management networks and firewall the service), since the flaw requires no credentials or user interaction. Given the high EPSS score, prioritize patching any internet-reachable instances and monitor for updates from HPE.

Affected
HPE Insight Remote Supportall versions prior to 7.15.0.646 (fixed in 7.15.0.646)
Estimated exposure
largeTens of thousands of IRS installations worldwide (order-of-magnitude estimate), with only a minority internet-exposed — No public install-base census or internet-scan counts exist for this optional on-prem appliance, so the figure is inferred from its deployment pattern — IRS is deployed by HPE enterprise support/monitoring customers and usually runs in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

Vendors
hpe
Products
insight remote support
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.