CVE-2025-27086: High severity hpe performance cluster manager vulnerability
Published Apr 21, 2025
·Updated
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
Affected Software
2 affected components
HPE Performance Cluster Manager
HPE Performance Cluster Manager<1.13
Event History
Apr 21, 2025
CVE Published
via MITRE·06:07 PM
Data Sourced
via MITRE·06:07 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27086?
CVE-2025-27086 is classified with a medium severity level.
2
How do I fix CVE-2025-27086?
To fix CVE-2025-27086, update HPE Performance Cluster Manager to version 1.13 or later.
3
What versions of HPE Performance Cluster Manager are affected by CVE-2025-27086?
CVE-2025-27086 affects HPE Performance Cluster Manager versions up to and including 1.12.
4
What impact does CVE-2025-27086 have on users?
CVE-2025-27086 may allow unauthorized access or modifications to the system for affected users.
5
Is there a workaround for CVE-2025-27086 until I can update?
While waiting to update, it's recommended to restrict access to the HPE Performance Cluster Manager interface.