HPE OneView Software Vulnerability Allows Remote Code Execution

Hewlett Packard Enterprise has released a critical security bulletin addressing a severe vulnerability in HPE OneView Software that could allow remote attackers to execute arbitrary code without authentication.

The vulnerability, tracked as CVE-2025-37164, affects all versions of HPE OneView before version 11.00 and poses an immediate risk to enterprise infrastructure management systems.

The flaw exists in the HPE OneView application framework and can be exploited by unauthenticated remote users to gain complete control over affected systems.

The vulnerability carries a maximum CVSS severity score of 10.0, indicating critical risk with no authentication requirements and network-accessible attack vectors.

HPE acknowledges the security researcher Brock200 (Nguyen Quoc Khanh) for discovering and responsibly reporting this vulnerability.

HPE has released comprehensive patches to resolve the security issue. Organizations running HPE OneView version 11.00 or later are protected against this vulnerability.

For users on earlier versions between 5.20 and 10.20, HPE provides security hotfixes available through their software center and support portals.

The fixes include both virtual appliance security hotfixes and HPE Synergy Composer security patches tailored for different deployment scenarios.

Enterprise customers should prioritize updating to the patched versions immediately, particularly those with public-facing OneView instances or multi-tenant environments.

Organizations unable to upgrade immediately must implement the security hotfixes and apply appropriate network segmentation to minimize exposure.

Security teams should review their OneView deployments and initiate patch management workflows without delay.

Vulnerability DetailInformation
CVE IdentifierCVE-2025-37164
Bulletin IDHPESBGN04985 rev.1
Attack VectorNetwork (AV:N)
Authentication RequiredNone (PR:N)
Attack ComplexityLow (AC:L)
User InteractionNot Required (UI:N)
Impact ScopeChanged (S:C)
Confidentiality ImpactHigh (C:H)
Integrity ImpactHigh (I:H)
Availability ImpactHigh (A:H)
CVSS v3.1 Score10.0 (Critical)
Affected VersionsAll versions prior to v11.00
Fixed Versionv11.00 and later
Release DateDecember 16, 2025
Reporterbrocked200 (Nguyen Quoc Khanh)

The bulletin recommends that all users determine the applicability of this information to their infrastructure and take appropriate patching actions.

HPE provides security hotfixes for OneView versions 5.20 through 10.20 via their enterprise license portal and official support channels.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories