logo

Hewlett Packard Enterprise warns of critical StoreOnce auth bypass

ID: 376c7784-093a-5d48-b5b4-43054cfd77a8

STIX ID: report--376c7784-093a-5d48-b5b4-43054cfd77a8

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-06-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Hewlett Packard Enterprise released a security bulletin for HPE StoreOnce Software v4.3.11 fixing eight vulnerabilities—including a critical authentication bypass (CVE-2025-37093, CVSS 9.8), multiple remote code execution bugs, directory traversal issues, and an SSRF—affecting all versions prior to v4.3.11; ZDI notes the authentication bypass can enable exploitation of the other flaws, and HPE recommends immediate upgrading since no mitigations are listed and no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.