GPU VulnDB

Database/Control plane, storage & DevOps

HPE StoreOnce: unauthenticated command injection allows remote code execution on the backup appliance

CVSS 9.8CVE-2025-37089Control plane, storage & DevOps+2 more CVEscurated

Impact

An unauthenticated attacker reaching the StoreOnce management interface can inject commands and execute code on the backup appliance. HPE split this across 3 CVE ids (CVE-2025-37089, CVE-2025-37092, CVE-2025-37096), one per injection path; all are the same flaw class in the same component with the same fix. Backup appliances hold copies of everything and are a primary ransomware target.

Who can reach it

Unauthenticated network access to StoreOnce.

What to do

Upgrade StoreOnce Software to the fixed release per HPESBST04847 (appliance upgrade, needs a service window). One upgrade closes all three ids, along with the other advisory issues. Restrict management-interface exposure to a trusted network in the meantime.

Also covers 2 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2025-37092CVE-2025-37096

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.