CVE-2025-37096: Command Injection
Published Jun 2, 2025
·Updated
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
Affected Software
2 affected components
Hewlett Packard Enterprise StoreOnce Software
HPE Storeonce System<4.3.11
Event History
Jun 2, 2025
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37096?
CVE-2025-37096 is categorized as a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-37096?
To mitigate CVE-2025-37096, update the HPE StoreOnce Software to the latest version provided by Hewlett Packard Enterprise.
3
What types of attacks can exploit CVE-2025-37096?
CVE-2025-37096 can be exploited through command injection attacks that allow unauthorized execution of code.
4
What versions of HPE StoreOnce Software are affected by CVE-2025-37096?
CVE-2025-37096 affects certain versions of the HPE StoreOnce Software, as specified by the vendor in security advisories.
5
Is there a workaround for CVE-2025-37096 if an update cannot be applied immediately?
Currently, there are no known workarounds for CVE-2025-37096, and applying the software update is strongly recommended.