VDB
CVE-2025-37164
CVE-2025-37164
PUBLISHED
KEV
CVSS 10 CRITICAL
A remote code execution issue exists in HPE OneView.
EPSS 79.59% · 99.1th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
79.59%
99.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hewlett Packard Enterprise (HPE) | HPE OneView | 0 |
| hpe | oneview | 0 |
Timeline
- May 31, 2022 CrowdSec Sighting
- Sep 24, 2022 CrowdSec Sighting
- Apr 28, 2023 CrowdSec Sighting
- May 31, 2023 CrowdSec Sighting
- Jul 15, 2024 CrowdSec Sighting
- Mar 2, 2025 CrowdSec Sighting
- Apr 16, 2025 CVE ID Reserved
- May 12, 2025 CrowdSec Sighting
- Jun 28, 2025 CrowdSec Sighting
- Dec 10, 2025 CrowdSec Sighting
- Dec 16, 2025 CVE Published
- Dec 16, 2025 PoC Published
References
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US url
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1 vendor-advisory
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-37164 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-37164 advisory
- https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn4985en_us&docLocale=en_US url