Critical HPE OneView vulnerability rated 10.0

Hewlett Packard Enterprise has released a patch for a critical vulnerability in OneView, its software for managing and automating servers, storage and networking. CVE-2025-37164 allows unauthenticated remote code execution and carries the maximum CVSS v3.1 base score of 10.0. Details are limited so far, but analysis by Rapid7 suggests the issue is likely tied to an unauthenticated REST API endpoint. All OneView versions before 11.00 are affected, and administrators should patch as soon as possible.

What this means for your organisation

OneView governs the foundation of the data centre. An attacker in control here has not compromised one server but the ability to control all of them. Infrastructure management tools typically sit in management networks that are treated as internal and safe, and are therefore rarely reviewed.

Berigo recommends

  • Upgrade to OneView 11.00 or later as soon as your change window allows.
  • Verify that the management interface is unreachable from any network users can access.
  • Review who actually holds administrative access to infrastructure management.
  • Check logs for unexpected API calls against OneView in the period before patching.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch