HomeSecurityHPE warns of critical vulnerability in OneView software

HPE warns of critical vulnerability in OneView software

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in its HPE OneView software that could allow attackers to execute arbitrary code remotely. The issue, codenamed CVE-2025-37164 , affects one of the company's key infrastructure management tools and has raised concerns in the enterprise cybersecurity community.

HPE OneView

What is HPE OneView and why is it critical?

HPE OneView is HPE's central infrastructure management platform, designed to simplify and automate the operation of servers, storage, and networking through a single environment. It is widely used in data centers and large organizations, as it offers unified visibility and control over complex IT infrastructures.

See also: Zeroday Cloud contest: $320,000 in prizes for 11 zero days

Precisely because of this role, any vulnerability in OneView takes on particular gravity: a successful attack could give an attacker extensive access to critical systems.

The CVE-2025-37164 vulnerability in simple terms

The vulnerability was reported by Vietnamese security researcher Nguyen Quoc Khanh (known as brocked200) and affects all versions of OneView prior to v11.00. According to HPE, the issue can be exploited by unauthorized users via attacks code injection , leading to remote code execution (RCE).

Simply put, an attacker does not need elevated privileges or sophisticated techniques to exploit the vulnerability, which dramatically raises the risk index.

HPE warns of critical vulnerability in OneView software

Warning without delay

In an official advisory, HPE clarified that there are no interim measures or workarounds. The only safe option for organizations is to immediately upgrade affected systems.

Although the company has not yet confirmed whether the vulnerability has been actively exploited in attacks, history shows that such RCE vulnerabilities are often quickly targeted by malicious actors, especially when they involve software widely used in enterprise environments.

See also: Amazon: Cryptomining campaign uses compromised AWS accounts

How can organizations protect themselves?

HPE recommends upgrading to OneView version 11.00 or later , which is available through the HPE Software Center. For systems running versions 5.20 through 10.20 , a security hotfix is ​​also available .

Special care is required in environments with HPE Synergy Composer, as the hotfix must be reapplied after certain upgrades or redesigns. HPE has made separate downloads available for the virtual appliance security hotfix and the Synergy security hotfix, through dedicated support pages.

A broader pattern of security challenges

The OneView case is not an isolated incident. In June, HPE patched eight vulnerabilities in StoreOnce (a critical authentication bypass bug, as well as multiple remote code execution vulnerabilities). Shortly after, in July, the company warned about hardcoded credentials in Aruba Instant On Access Points, which could allow unauthorized access to the web interface.

These incidents highlight how difficult it has become to protect complex enterprise products in an ever-evolving threat landscape.

HPE warns of critical vulnerability in OneView software

What does this mean for corporate security?

With more than 61,000 employees, revenue of $30.1 billion in 2024 , and a customer base that includes more than 55,000 organizations – including 90% of the Fortune 500 – HPE is at the core of the global IT infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: CISA: ASUS Live Update Vulnerability in KEV Catalog

The OneView vulnerability serves as a stark reminder that early notification and continuous monitoring are not just best practices, but necessary survival requirements for modern businesses. In an era where a single RCE vulnerability can lead to a complete breach, speed of response makes all the difference.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS