CVE-2025-37089: Command Injection
Published Jun 2, 2025
·Updated
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Affected Software
2 affected components
Hewlett Packard Enterprise StoreOnce Software
HPE Storeonce System<4.3.11
Event History
Jun 2, 2025
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37089?
CVE-2025-37089 is characterized as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-37089?
To mitigate CVE-2025-37089, it is recommended to apply the latest security patches provided by Hewlett Packard Enterprise for StoreOnce Software.
3
What types of attacks can exploit CVE-2025-37089?
CVE-2025-37089 can be exploited through command injection attacks that allow attackers to execute arbitrary commands on the vulnerable system.
4
What systems are affected by CVE-2025-37089?
CVE-2025-37089 specifically affects HPE StoreOnce Software and the versions currently in deployment.
5
What are the potential consequences of exploiting CVE-2025-37089?
Exploitation of CVE-2025-37089 can lead to complete system compromise, unauthorized data access, and disruption of services.