CVE-2025-37092: Command Injection
Published Jun 2, 2025
·Updated
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Affected Software
2 affected components
Hewlett Packard Enterprise StoreOnce Software
HPE Storeonce System<4.3.11
Event History
Jun 2, 2025
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37092?
CVE-2025-37092 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2025-37092?
To remediate CVE-2025-37092, apply the latest security patches provided by HPE for StoreOnce Software.
3
What systems are affected by CVE-2025-37092?
CVE-2025-37092 affects the Hewlett Packard Enterprise StoreOnce Software.
4
What types of attacks can exploit CVE-2025-37092?
CVE-2025-37092 can be exploited through command injection, allowing remote attackers to execute arbitrary code.
5
Is there a workaround for CVE-2025-37092?
Currently, the recommended approach for CVE-2025-37092 is to update to a patched version of the software, as there are no known effective workarounds.