CVE-2025-37112: Hard-Coded Encryption Keys found in System
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37112?
CVE-2025-37112 has high severity due to the potential for unauthorized access to sensitive system information.
How do I fix CVE-2025-37112?
To mitigate CVE-2025-37112, it is recommended to update the HPE Telco Network Function Virtual Orchestrator to the latest patch provided by Hewlett Packard Enterprise.
What software is affected by CVE-2025-37112?
CVE-2025-37112 affects the HPE Telco Network Function Virtual Orchestrator.
What can attackers do with the CVE-2025-37112 vulnerability?
Attackers exploiting CVE-2025-37112 can gain unauthorized access to sensitive system information.
Is there a public disclosure for CVE-2025-37112?
Yes, CVE-2025-37112 has been publicly disclosed with pertinent details available from HPE support.