CVE-2025-37099: Code Injection
Published Jul 1, 2025
·Updated
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
Affected Software
2 affected components
HPE Insight Remote Support<7.15.0.646
HPE Insight Remote Support<7.15.0.646
Event History
Jul 1, 2025
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37099?
CVE-2025-37099 is classified as a remote code execution vulnerability.
2
How do I fix CVE-2025-37099?
To fix CVE-2025-37099, upgrade HPE Insight Remote Support to version 7.15.0.646 or later.
3
What software is impacted by CVE-2025-37099?
CVE-2025-37099 affects HPE Insight Remote Support prior to version 7.15.0.646.
4
Can CVE-2025-37099 be exploited remotely?
Yes, CVE-2025-37099 allows for remote code execution, making it exploitable from an external network.
5
What are the risks associated with CVE-2025-37099?
The risks associated with CVE-2025-37099 include unauthorized remote code execution on affected systems.