HPE OneView Vulnerability: When Your Data Center Gets an Unwanted Remote Control
Hewlett Packard Enterprise (HPE) has patched a critical OneView flaw, tracked as CVE-2025-37164, scoring a perfect 10.0 on the CVSS scale. This vulnerability allowed attackers to potentially achieve remote code execution, but rest assured, HPE has hit Ctrl+Z on this bug. Keep calm and update your servers.

Hot Take:
It looks like Hewlett Packard Enterprise’s OneView is having a bit of an identity crisis. It went from being a secure IT management platform to an open invite for cyber mischief! But fear not, HPE has swooped in with their digital duct tape to fix the mess. Can someone pass the popcorn while we watch this cybersecurity soap opera unfold?
Key Points:
- HPE fixed a critical vulnerability in its OneView software, tracked as CVE-2025-37164, with a perfect 10 CVSS score.
- The flaw allowed potential remote code execution by unauthenticated users.
- All versions of OneView through v10.20 were impacted.
- In June, HPE addressed eight vulnerabilities in its StoreOnce backup solution, including authentication bypass and remote code execution.
- There is no confirmation yet on whether the OneView flaw has been exploited in the wild.
Already a member? Log in here
