ZDI-CAN-24982: ZDI-25-313: Hewlett Packard Enterprise StoreOnce VSA determineInclusionAndExtract Server-Side Request Forgery Vulnerability
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2025-37090.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24982?
The CVSS rating of ZDI-CAN-24982 is 5.3, indicating a medium-severity vulnerability.
What does ZDI-CAN-24982 allow attackers to do?
ZDI-CAN-24982 allows remote attackers to initiate arbitrary server-side requests without requiring authentication.
Which software is affected by ZDI-CAN-24982?
ZDI-CAN-24982 affects Hewlett Packard Enterprise StoreOnce VSA installations.
Do I need to be authenticated to exploit ZDI-CAN-24982?
No, ZDI-CAN-24982 can be exploited without any authentication.
How can I mitigate the risks associated with ZDI-CAN-24982?
To mitigate ZDI-CAN-24982, ensure that you apply any available security patches and limit access to the affected service.