ZDI-CAN-25789: ZDI-25-612: Hewlett Packard Enterprise AutoPass License Server Hard-coded Credentials Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise AutoPass License Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-37105.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25789?
The severity of ZDI-CAN-25789 is rated at 7.5 on the CVSS scale.
How do I fix ZDI-CAN-25789?
To fix ZDI-CAN-25789, update the Hewlett Packard Enterprise AutoPass License Server to the latest patched version.
Who is affected by ZDI-CAN-25789?
Organizations using affected installations of Hewlett Packard Enterprise AutoPass License Server are at risk from ZDI-CAN-25789.
Is authentication required to exploit ZDI-CAN-25789?
No, authentication is not required to exploit the ZDI-CAN-25789 vulnerability.
What type of attack can ZDI-CAN-25789 facilitate?
ZDI-CAN-25789 allows network-adjacent attackers to execute arbitrary code on affected installations.