A maximum-severity security vulnerability in OneView Software that, if successfully exploited, might lead to remote code execution has been fixed by Hewlett Packard Enterprise (HPE).
The major vulnerability has a CVSS score of 10.0 and is assigned the CVE identifier CVE-2025-37164. HPE OneView is an IT infrastructure management program that uses a common dashboard interface to manage all systems and streamline IT operations.
The Hewlett Packard Enterprise OneView Software has a possible security flaw. In a warning released this week, HPE stated that this vulnerability may be abused to enable remote code execution by an unauthorized user.
All software versions until version 11.00, which fixes the bug, are impacted. Additionally, a hotfix for OneView versions 5.20 through 10.20 has been made available by the company read more about HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
