HPE tells customers to patch fast as OneView RCE bug scores a perfect 10
ID: 5b8a1920-b922-5bb8-aa74-fe0ce772c388
STIX ID: report--5b8a1920-b922-5bb8-aa74-fe0ce772c388
Feed Name: The Register (Security)
HPE OneView contains a maximum-severity unauthenticated remote code execution flaw (CVE-2025-37164, CVSS 10.0) affecting versions 5.20–10.20; HPE urges immediate upgrade to 11.0 or application of emergency hotfixes (separate fixes for virtual appliance and Synergy). Rapid7's analysis indicates the primary vector is a REST API endpoint that the hotfix blocks at the web server level, and defenders are advised to treat the issue as an assumed-breach scenario given OneView's high-privilege position in enterprise infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
