CVE-2025-37164 is a critical remote code execution (RCE) vulnerability affecting HPE OneView. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and reports of botnet targeting. Exploit modules are publicly available, including a Metasploit module and Nuclei templates, leading to significant community discussion and media coverage. Organizations are urged to patch immediately to OneView v11.00 or later to mitigate this severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.20.00CPE matchmatch criteria | cpe:2.3:a:hpe:oneview:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.