PT-2025-51738 · Hewlett Packard · Hpe Oneview
Published
2025-12-16
·
Updated
2026-05-01
·
CVE-2025-37164
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
HPE OneView versions prior to 11.00
Description
A critical code injection issue exists in HPE OneView, a centralized management platform for servers, storage, and networking. The flaw stems from improper input handling in a publicly accessible REST API endpoint, allowing unauthenticated remote attackers to bypass authentication and execute arbitrary commands. This can lead to complete system compromise, potentially granting attackers control over core infrastructure components, privilege escalation, data exfiltration, or operational disruption. This issue has been actively exploited in the wild.
Recommendations
Update to version 11.00 or later.
For versions 5.20 through 10.20, deploy the specific fix; note that this fix must be reapplied after updating from version 6.60 or later to version 7.00.00, or after any system reinstallation using HPE Synergy Composer.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hpe Oneview