ZDI-25-612: Hewlett Packard Enterprise AutoPass License Server Hard-coded Credentials Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise AutoPass License Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-37105.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-612?
The severity of ZDI-25-612 is rated at 7.5 according to the CVSS scale.
How do I fix ZDI-25-612?
To fix ZDI-25-612, apply the latest security patch provided by Hewlett Packard Enterprise for the AutoPass License Server.
What type of attacks can exploit ZDI-25-612?
ZDI-25-612 allows network-adjacent attackers to execute arbitrary code on the affected installations.
Is authentication required to exploit ZDI-25-612?
No, authentication is not required to exploit the ZDI-25-612 vulnerability.
Which software is affected by ZDI-25-612?
The affected software for ZDI-25-612 is the Hewlett Packard Enterprise AutoPass License Server.