Skip to content
COOEY

EXPOSURES › CVE-2025-37164

CVE-2025-37164

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-01-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-37164 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

HPE OneView exposed to remote code execution due to unpatched code injection vulnerability.

Hewlett Packard Enterprise's OneView suffered an unpatched code injection flaw, allowing remote, unauthenticated attackers to execute arbitrary code, posing a high-severity risk to DIB organizations.

Shame score — Unpatched vulnerability enabling remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.