Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
ID: 376c7784-093a-5d48-b5b4-43054cfd77a8
STIX ID: report--376c7784-093a-5d48-b5b4-43054cfd77a8
Feed Name: Bleeping Computer
Hewlett Packard Enterprise released a security bulletin for HPE StoreOnce Software v4.3.11 fixing eight vulnerabilities—including a critical authentication bypass (CVE-2025-37093, CVSS 9.8), multiple remote code execution bugs, directory traversal issues, and an SSRF—affecting all versions prior to v4.3.11; ZDI notes the authentication bypass can enable exploitation of the other flaws, and HPE recommends immediate upgrading since no mitigations are listed and no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
