CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
Published Dec 16, 2025
·Updated
A remote code execution issue exists in HPE OneView.
Other sources
Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
— CISA
Affected Software
2 affected components
HPE OneView<=10.20.00
Hewlett Packard Enterprise (HPE) OneView
Event History
Dec 16, 2025
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Dec 18, 2025
News Published
via BleepingComputer·11:35 AM
News Published
via BleepingComputer·11:37 AM
Dec 19, 2025
News Published
via The Register·01:03 PM
News Published
via The Register·01:06 PM
Jan 7, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Jan 8, 2026
News Published
via BleepingComputer·07:45 AM
News Published
via The Register·01:44 PM
Jan 16, 2026
News Published
via The Register·01:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-37164?
CVE-2025-37164 is classified as a maximum severity remote code execution vulnerability.
2
Which versions of HPE OneView are affected by CVE-2025-37164?
CVE-2025-37164 affects HPE OneView versions from 5.20 to 10.20 inclusive.
3
How do I fix CVE-2025-37164?
To address CVE-2025-37164, update HPE OneView to a version that exceeds 10.20.
4
What type of vulnerability is CVE-2025-37164?
CVE-2025-37164 is a remote code execution vulnerability.
5
Can exploiting CVE-2025-37164 lead to severe consequences?
Yes, exploiting CVE-2025-37164 can allow attackers to execute arbitrary code remotely, potentially leading to unauthorized access and control.