CVE-2025-37164

9.5 CISA KEV

Hewlett Packard Enterprise (HPE) · OneView

A critical remote code execution vulnerability exists in HPE OneView, allowing unauthenticated attackers to execute arbitrary code with elevated privileges.

Executive summary

HPE OneView is susceptible to a critical remote code execution vulnerability that is currently being actively exploited in the wild.

Vulnerability

This is a code injection vulnerability that results in remote code execution. The vulnerability is exploitable by unauthenticated attackers over the network with no user interaction required.

Business impact

The exploitation of this vulnerability allows for total system compromise, including full control over the OneView appliance. Given the CVSS score of 9.5, the business impact is severe, potentially leading to unauthorized data access, lateral movement within the data center, and significant operational disruption.

Remediation

Immediate Action: Update all instances of HPE OneView to version 11.00 or later as specified in the vendor security advisory.

Proactive Monitoring: Monitor network traffic for suspicious inbound connections to OneView management interfaces and audit system logs for unauthorized command execution or unexpected service modifications.

Compensating Controls: Restrict access to the OneView management interface to trusted administrative IP addresses using network-level controls or a VPN until the update can be applied.

Exploitation status

Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability and the confirmed active exploitation in the wild, organizations must prioritize the remediation of all vulnerable HPE OneView instances immediately. Failure to patch these systems leaves the infrastructure highly susceptible to full compromise by remote, unauthenticated threat actors.

More Hewlett Packard Enterprise (HPE) CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief kev section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Analyst report written
  24. Fix documented version 11.00 per CVE record

Sources