Hewlett Packard Enterprise (HPE) is warning of eight serious vulnerabilities in StoreOnce — its disk-based backup and deduplication solution. The vulnerabilities, discovered by the Zero Day Initiative (ZDI), affect all versions of the software prior to v4.3.11, which users are now advised to install immediately.

Critical vulnerability with a rating of 9.8/10
Among the vulnerabilities CVE-2025-37093, a critical vulnerability with a CVSS score of 9.8. It allows authentication bypass and is due to an incorrect implementation of the machineAccountCheck. According to ZDI, the error is related to a faulty authentication algorithm, creating a serious risk of unauthorized access.
See also: SolarWinds Dameware Vulnerability Allows Privilege Escalation
In addition to this, the 4.3.11 fix pack includes:
- Four security vulnerabilities that allow remote code execution (RCE)
- Two directory traversal vulnerabilities, which could allow file deletion or disclosure
- A server-side request forgery (SSRF) bug
The eight vulnerabilities that were fixed:
- CVE-2025-37089 – Remote Code Execution
- CVE-2025-37090 – Server-Side Request Forgery
- CVE-2025-37091 – Remote Code Execution
- CVE-2025-37092 – Remote Code Execution
- CVE-2025-37093 – Authentication Bypass
- CVE-2025-37094 – File deletion via Directory Traversal
- CVE-2025-37095 – Information Disclosure via Directory Traversal
- CVE-2025-37096 – Remote Code Execution
Strengthen your security
While HPE has not released full technical details of each flaw, the severity of the situation is undeniable. System administrators are urged to immediately upgrade their software to StoreOnce version 4.3.11to reduce the chances of a successful attack and ensure the integrity of their systems.
Although CVE-2025-37093 is the only critical, security experts say the others shouldn't be underestimated. According to the Zero Day Initiative (ZDI), many of the other vulnerabilities, while rated as "medium severity," become much more significant when combined with authentication bypass.
See also: Google fixes new zero-day vulnerability in Chrome browser
Specifically, ZDI notes that CVE-2025-37093 acts as a "key" that unlocks the conditions for the exploitation of other vulnerabilities in HPE StoreOnce. For example, CVE-2025-37094 (file deletion) and CVE-2025-37095 (information disclosure) appear to be much more exploitable in practice than their theoretical scores suggest.
Seven-month delay in corrections
It is worth noting that these issues were reported to HPE in October 2024, but the official patch release was delayed by about seven months. So far, there are no reports of active exploitation of the vulnerabilities, which gives administrators a short window of time to react immediately.
HPE StoreOnce is a core solution for data backup and recovery in large enterprises, data centers and cloud service providers. It integrates with platforms such as HPE Data Protector, Veeam, Commvault and Veritas NetBackup, supporting critical infrastructure continuity and disaster recovery.
System and security administrators in environments using StoreOnce are urged to immediately upgrade to version 4.3.11to limit the possibility of data breach and loss.
See also: Qualcomm fixes zero-day vulnerabilities in Adreno GPU driver

Hewlett Packard Enterprise (HPE), in its security bulletin, does not provide any workarounds for the eight vulnerabilities identified in StoreOnce. Therefore, upgrading remains the only recommended action to fully eliminate the risks.
In general, however, various safeguards should be implemented to avoid such situations. For example, it is important to strengthen access control by implementing multi-factor authentication (where possible) and enabling logging and storing log files externally.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Also, ensure that system administrators understand the importance of upgrading and that data recovery policies are up-to-date and tested.
This incident is a good reminder that ( security solutions like backup systems) are not inherently secure. They must be actively protected — with continuous updates, access restrictions, and activity monitoring. If you use HPE StoreOnce, inaction is not an option.
Source: www.bleepingcomputer.com
