HomeSecurityHPE warns of vulnerabilities in StoreOnce

HPE warns of vulnerabilities in StoreOnce

Hewlett Packard Enterprise (HPE) is warning of eight serious vulnerabilities in StoreOnce — its disk-based backup and deduplication solution. The vulnerabilities, discovered by the Zero Day Initiative (ZDI), affect all versions of the software prior to v4.3.11, which users are now advised to install immediately.

Hewlett Packard Enterprise HPE StoreOnce vulnerabilities

Critical vulnerability with a rating of 9.8/10

Among the vulnerabilities CVE-2025-37093, a critical vulnerability with a CVSS score of 9.8. It allows authentication bypass and is due to an incorrect implementation of the machineAccountCheck. According to ZDI, the error is related to a faulty authentication algorithm, creating a serious risk of unauthorized access.

See also: SolarWinds Dameware Vulnerability Allows Privilege Escalation

In addition to this, the 4.3.11 fix pack includes:

  • Four security vulnerabilities that allow remote code execution (RCE)
  • Two directory traversal vulnerabilities, which could allow file deletion or disclosure
  • A server-side request forgery (SSRF) bug

The eight vulnerabilities that were fixed:

  • CVE-2025-37089 – Remote Code Execution
  • CVE-2025-37090 – Server-Side Request Forgery
  • CVE-2025-37091 – Remote Code Execution
  • CVE-2025-37092 – Remote Code Execution
  • CVE-2025-37093 – Authentication Bypass
  • CVE-2025-37094 – File deletion via Directory Traversal
  • CVE-2025-37095 – Information Disclosure via Directory Traversal
  • CVE-2025-37096 – Remote Code Execution

Strengthen your security

While HPE has not released full technical details of each flaw, the severity of the situation is undeniable. System administrators are urged to immediately upgrade their software to StoreOnce version 4.3.11to reduce the chances of a successful attack and ensure the integrity of their systems.

Although CVE-2025-37093 is the only critical, security experts say the others shouldn't be underestimated. According to the Zero Day Initiative (ZDI), many of the other vulnerabilities, while rated as "medium severity," become much more significant when combined with authentication bypass.

See also: Google fixes new zero-day vulnerability in Chrome browser

Specifically, ZDI notes that CVE-2025-37093 acts as a "key" that unlocks the conditions for the exploitation of other vulnerabilities in HPE StoreOnce. For example, CVE-2025-37094 (file deletion) and CVE-2025-37095 (information disclosure) appear to be much more exploitable in practice than their theoretical scores suggest.

Seven-month delay in corrections

It is worth noting that these issues were reported to HPE in October 2024, but the official patch release was delayed by about seven months. So far, there are no reports of active exploitation of the vulnerabilities, which gives administrators a short window of time to react immediately.

HPE StoreOnce is a core solution for data backup and recovery in large enterprises, data centers and cloud service providers. It integrates with platforms such as HPE Data Protector, Veeam, Commvault and Veritas NetBackup, supporting critical infrastructure continuity and disaster recovery.

System and security administrators in environments using StoreOnce are urged to immediately upgrade to version 4.3.11to limit the possibility of data breach and loss.

See also: Qualcomm fixes zero-day vulnerabilities in Adreno GPU driver

HPE warns of vulnerabilities in StoreOnce

Hewlett Packard Enterprise (HPE), in its security bulletin, does not provide any workarounds for the eight vulnerabilities identified in StoreOnce. Therefore, upgrading remains the only recommended action to fully eliminate the risks.

In general, however, various safeguards should be implemented to avoid such situations. For example, it is important to strengthen access control by implementing multi-factor authentication (where possible) and enabling logging and storing log files externally.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, ensure that system administrators understand the importance of upgrading and that data recovery policies are up-to-date and tested.

This incident is a good reminder that ( security solutions like backup systems) are not inherently secure. They must be actively protected — with continuous updates, access restrictions, and activity monitoring. If you use HPE StoreOnce, inaction is not an option.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS