Database/Control plane, storage & DevOps

HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView appliance
CVSS 7.8CVE-2023-50274Control plane, storage & DevOpscurated
Impact
A low-privileged local user on the OneView appliance injects commands and escalates - full control of the fleet management appliance.
Who can reach it
Local low-privilege access to the OneView appliance.
What to do
Apply the OneView update per HPESBGN04586. Appliance update with restart.
References
Related entries
- OpenVPN: Stack overflow in the interactive serviceCVE-2024-27459 · OpenVPNHigh
- Intel QuickAssist Technology (QAT) software and driversCVE-2024-31858 · Intel QuickAssist Technology (QAT) software and drivers - QAT software before 2.2.0, with a 2025 batch through 2.6.0High
- IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableCVE-2024-31891 · IBM Storage Scale GUI (local privilege escalation)High
- Linux HID/amd_sfh - driver_data freed after HID device destruction: A use-after-free in the AMD Sensor Fusion Hub HIDCVE-2024-46746 · Linux HID/amd_sfh - driver_data freed after HID device destructionHigh
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- ansible-core: malicious Galaxy role injects git flags to run code on the machine installing itCVE-2026-11332 · ansible-core (ansible-galaxy role install, git argument injection via meta/requirements.yml)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.