Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Posted on December 18, 2025December 18, 2025 By CWS

Dec 18, 2025Ravie LakshmananVulnerability / Enterprise Safety
Hewlett Packard Enterprise (HPE) has resolved a maximum-severity safety flaw in OneView Software program that, if efficiently exploited, may lead to distant code execution.
The essential vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS rating of 10.0. HPE OneView is an IT infrastructure administration software program that streamlines IT operations and controls all methods through a centralized dashboard interface.
“A possible safety vulnerability has been recognized in Hewlett Packard Enterprise OneView Software program. This vulnerability might be exploited, permitting a distant unauthenticated person to carry out distant code execution,” HPE stated in an advisory issued this week.

It impacts all variations of the software program previous to model 11.00, which addresses the flaw. The corporate has additionally made obtainable a hotfix that may be utilized to OneView variations 5.20 via 10.20.
It is price noting that the hotfix have to be reapplied after upgrading from model 6.60 or later to model 7.00.00, or after any HPE Synergy Composer reimaging operations. Separate hotfixes can be found for the OneView digital equipment and Synergy Composer2.
Though HPE makes no point out of the flaw being exploited within the wild, it is important that customers apply the patches as quickly as attainable for optimum safety.
Earlier this June, the corporate additionally launched updates to repair eight vulnerabilities in its StoreOnce information backup and deduplication resolution that might lead to an authentication bypass and distant code execution. It additionally shipped OneView model 10.00 to remediate a lot of recognized flaws in third-party elements, akin to Apache Tomcat and Apache HTTP Server.

The Hacker News Tags:Code, CVSS, Execution, Flaw, HPE, OneView, Rated, Remote, Unauthenticated

Post navigation

Previous Post: CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation
Next Post: HPE Patches Critical Flaw in IT Infrastructure Management Software

Related Posts

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases The Hacker News
Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features Android Malware FvncBot, SeedSnatcher, and ClayRat Gain Stronger Data Theft Features The Hacker News
Reynolds Ransomware Uses Vulnerable Driver to Bypass Security Reynolds Ransomware Uses Vulnerable Driver to Bypass Security The Hacker News
Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors The Hacker News
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine The Hacker News
Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark