Database/Control plane, storage & DevOps

HPE StoreOnce: unauthenticated command injection allows remote code execution on the backup appliance
Impact
An unauthenticated attacker reaching the StoreOnce management interface can inject commands and execute code on the backup appliance. HPE split this across 3 CVE ids (CVE-2025-37089, CVE-2025-37092, CVE-2025-37096), one per injection path; all are the same flaw class in the same component with the same fix. Backup appliances hold copies of everything and are a primary ransomware target.
Who can reach it
Unauthenticated network access to StoreOnce.
What to do
Upgrade StoreOnce Software to the fixed release per HPESBST04847 (appliance upgrade, needs a service window). One upgrade closes all three ids, along with the other advisory issues. Restrict management-interface exposure to a trusted network in the meantime.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- HPE StoreOnce (server-side request forgery): SSRF from the backup appliance, letting an unauthenticated attacker pivotCVE-2025-37090 · HPE StoreOnce (server-side request forgery)Critical
- HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gainingCVE-2025-37093 · HPE StoreOnce (authentication bypass)Critical
- HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCVE-2025-37095 · HPE StoreOnce (directory traversal information disclosure)Critical
- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCVE-2025-37099 · HPE Insight Remote Support (remote code execution)Critical
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCVE-2025-38430 · Linux NFS server (nfsd, nfsd4_spo_must_allow)Critical
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCVE-2025-40212 · Linux NFS server (nfsd, nfsd_set_fh_dentry)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.