logo

HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

ID: 5b8a1920-b922-5bb8-aa74-fe0ce772c388

STIX ID: report--5b8a1920-b922-5bb8-aa74-fe0ce772c388

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-12-19

Date Updated: 2026-04-26

Author: Carly Page

...
...

HPE OneView contains a maximum-severity unauthenticated remote code execution flaw (CVE-2025-37164, CVSS 10.0) affecting versions 5.20–10.20; HPE urges immediate upgrade to 11.0 or application of emergency hotfixes (separate fixes for virtual appliance and Synergy). Rapid7's analysis indicates the primary vector is a REST API endpoint that the hotfix blocks at the web server level, and defenders are advised to treat the issue as an assumed-breach scenario given OneView's high-privilege position in enterprise infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.