Hewlett Packard Enterprise (HPE) has patched a maximum-severity vulnerability in its HPE OneView software that enables attackers to execute arbitrary code remotely. OneView is HPE's infrastructure management software that helps IT admins streamline operations and automate the management of servers, storage, and networking devices from a centralized interface. This critical security flaw (CVE-2025-37164) was reported by Vietnamese security researcher Nguyen Quoc Khanh (brocked200) to the company's security team. It affects all OneView versions released before v11.00 and can be exploited by unauthenticated threat actors in low-complexity code injection attacks to gain remote code execution on unpatched systems. "A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution," HPE warned in a Tuesday advisory. There are no workarounds or mitigations for CVE-2025-37164, so admins are advised to patch vulnerable systems as soon as possible. HPE has yet to confirm whether this vulnerability has been targeted in attacks and says that affected organizations can upgrade to OneView version 11.00 or later, available through HPE's Software Center, to patch it. On devices running OneView versions 5.20 through 10.20, the vulnerability can be addressed by deploying a security hotfix, which must be reapplied after upgrading from version 6.60 ...
HPE warns of maximum severity RCE flaw in OneView software
BleepingComputer
·Sergiu Gatlan
·Published Dec 18, 2025
·Updated
Affected Software
1 affected component
Hewlett Packard Enterprise OneView
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a maximum-severity remote code execution vulnerability in HPE's OneView software.
2
What security implications are discussed in the article?
The article highlights that the vulnerability allows attackers to execute arbitrary code remotely, posing a significant risk to systems using OneView.
3
What products or software are affected by the vulnerability?
The vulnerability specifically affects Hewlett Packard Enterprise's OneView software.
4
What actions has HPE taken in response to the vulnerability?
HPE has released a patch to address the maximum-severity vulnerability in OneView software.
5
Who primarily uses HPE OneView software?
HPE OneView is primarily used by IT administrators for infrastructure management and server automation.