Maximum Severity HPE OneView Flaw Exploited in the Wild
ID: 8406f545-f9ae-56ae-92a9-33257099c11c
STIX ID: report--8406f545-f9ae-56ae-92a9-33257099c11c
Feed Name: Dark Reading
A critical unauthenticated remote code execution vulnerability (CVE-2025-37164, CVSS 10) affecting HPE OneView — an infrastructure management/control-plane product — was disclosed and patched (hotfixes for versions 5.20 through 10.20). CISA added the flaw to its Known Exploited Vulnerabilities catalog and reported it has come under attack, though HPE and Rapid7 state there are no confirmed customer exploitation reports; defenders are advised to treat it as an assumed-breach scenario and apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
