CRITICAL
CVE-2025-37164
CVSS
9.8
KEV
Description
A remote code execution issue exists in HPE OneView.
Summary dbcve.org
A critical remote code execution vulnerability exists in HPE OneView, allowing attackers to execute arbitrary code on the affected system without authentication. The CVSS 9.8 score indicates network-exploitable vector with complete impact to confidentiality, integrity, and availability.
Mitigation
Apply vendor-provided patches or updates for HPE OneView as soon as available; isolate affected systems from untrusted networks until patched.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
90.19%
Probability of exploitation in next 30 days
99.8th percentile
References
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US
Vendor Advisory
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb
Exploit
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-37164
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.