logo

HPE warns of maximum severity RCE flaw in OneView software

ID: 93f17462-69e2-53c7-b87b-8971503a0eb9

STIX ID: report--93f17462-69e2-53c7-b87b-8971503a0eb9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Hewlett Packard Enterprise disclosed and patched CVE-2025-37164, a critical unauthenticated code-injection vulnerability in HPE OneView (affecting all versions before 11.00) that can lead to remote code execution; no mitigations exist so administrators must upgrade to OneView 11.00 or apply vendor hotfixes for affected releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.