CVE-2025-37164
9.5 CISA KEVHewlett Packard Enterprise (HPE) · OneView
A critical remote code execution vulnerability exists in HPE OneView, allowing unauthenticated attackers to execute arbitrary code with elevated privileges.
Executive summary
HPE OneView is susceptible to a critical remote code execution vulnerability that is currently being actively exploited in the wild.
Vulnerability
This is a code injection vulnerability that results in remote code execution. The vulnerability is exploitable by unauthenticated attackers over the network with no user interaction required.
Business impact
The exploitation of this vulnerability allows for total system compromise, including full control over the OneView appliance. Given the CVSS score of 9.5, the business impact is severe, potentially leading to unauthorized data access, lateral movement within the data center, and significant operational disruption.
Remediation
Immediate Action: Update all instances of HPE OneView to version 11.00 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor network traffic for suspicious inbound connections to OneView management interfaces and audit system logs for unauthorized command execution or unexpected service modifications.
Compensating Controls: Restrict access to the OneView management interface to trusted administrative IP addresses using network-level controls or a VPN until the update can be applied.
Exploitation status
Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.
Analyst recommendation
Due to the critical nature of this vulnerability and the confirmed active exploitation in the wild, organizations must prioritize the remediation of all vulnerable HPE OneView instances immediately. Failure to patch these systems leaves the infrastructure highly susceptible to full compromise by remote, unauthenticated threat actors.
More Hewlett Packard Enterprise (HPE) CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 11.00 per CVE record