ZeroHour
Security Affairspublished ()ingested @securityaffairs

Hewlett Packard Enterprise (HPE) fixed maximum severity OneView flaw

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-37093
An authentication bypass vulnerability exists in HPE StoreOnce Software.

An authentication bypass vulnerability exists in HPE StoreOnce Software.

NVD description · AI analysis pending
9.81%
  • hpe storeonce system
CVE-2025-37164
Unauthenticated Remote Code Execution in HPE OneView

HPE OneView, HPE's infrastructure management platform, contains a code-injection flaw (CWE-94) that permits unauthenticated remote code execution, with a network-vector, low-complexity CVSS 3.1 score of 9.8 meaning no credentials, privileges, or user interaction are required. An attacker triggers the flaw by sending crafted code-injection input to the OneView appliance over the network, gaining code execution with high impact on the confidentiality, integrity, and availability of the appliance. A compromised OneView instance can serve as a foothold into the HPE server estate it manages, and the RondoDox botnet has already been observed folding this flaw into its exploitation waves. Any organization running an HPE OneView appliance is affected, particularly where the appliance is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, a public Metasploit exploit module is available, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile).

Do: Upgrade OneView to the fixed release specified in the HPE security bulletin for CVE-2025-37164 (exact version numbers are not included in this data), and treat patching as urgent given confirmed in-the-wild exploitation and the public Metasploit module. Until patched, remove unnecessary internet exposure of the OneView appliance and review appliance and network logs for signs of compromise, including possible RondoDox botnet infection. US federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.

9.890% KEV PoC
  • HPE OneView
large≈ tens of thousands of deployed OneView appliance instances worldwide, with the internet-exposed subset likely in the thousands
Full article315 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 18, 2025

Hewlett Packard Enterprise (HPE) fixed a critical OneView flaw that could allow attackers to achieve remote code execution.

Hewlett Packard Enterprise (HPE) addressed a maximum-severity security vulnerability, tracked as CVE-2025-37164 (CVSS score of 10.0), in OneView Software. An attacker can exploit the flaw to achieve remote code execution.

HPE OneView is an integrated IT management and automation platform by Hewlett Packard Enterprise used to manage, monitor, and automate HPE data center infrastructure.

It provides a single, software-defined interface to control servers, storage, and networking, mainly in HPE environments (e.g., ProLiant servers and Synergy systems).

“A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution.” reads the advisory published by the company.

The flaw impacts all versions through v10.20.

It is unclear if the threat actors have already exploited the vulnerability in attacks in the wild.

In June, HPE released security patches for eight vulnerabilities in its StoreOnce backup solution. These issues could allow remote code execution, authentication bypass, data leaks, and more.

“Potential security vulnerabilities have been identified in HPE StoreOnce Software.” reads the advisory. “These vulnerabilities could be remotely exploited to allow remote code execution, disclosure of information, server-side request forgery, authentication bypass, arbitrary file deletion, and directory traversal information disclosure vulnerabilities.”

The most severe vulnerability is an Authentication Bypass issue tracked as CVE-2025-37093 (CVSS score of 9,8). Earlier this June, the company also released updates to fix eight vulnerabilities in its StoreOnce data backup and deduplication solution that could result in an authentication bypass and remote code execution. It also shipped OneView version 10.00 to remediate a number of known flaws in third-party components, such as Apache Tomcat and Apache HTTP Server.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, HPE)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185853/security/hewlett-packard-enterprise-hpe-fixed-maximum-severity-oneview-flaw.html