CVE-2025-37091: Command Injection
Published Jun 2, 2025
·Updated
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Affected Software
2 affected components
HPE StoreOnce Software
HPE Storeonce System<4.3.11
Event History
Jun 2, 2025
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37091?
CVE-2025-37091 is classified as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-37091?
To fix CVE-2025-37091, users should apply the latest security updates provided by HPE for StoreOnce Software.
3
What type of vulnerability is CVE-2025-37091?
CVE-2025-37091 is a command injection vulnerability that allows for remote code execution.
4
What systems are affected by CVE-2025-37091?
CVE-2025-37091 affects HPE StoreOnce Software versions that have not been patched against this vulnerability.
5
What are the potential impacts of CVE-2025-37091?
Exploitation of CVE-2025-37091 could lead to unauthorized remote access and control of affected systems.