Database/Control plane, storage & DevOps

HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing files
CVSS 9.8CVE-2025-37095Control plane, storage & DevOpscurated
Impact
Unauthenticated directory traversal disclosing files from the backup appliance.
Who can reach it
Unauthenticated network access.
What to do
Upgrade StoreOnce per HPESBST04847.
References
Related entries
- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCVE-2025-37099 · HPE Insight Remote Support (remote code execution)Critical
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCVE-2025-38430 · Linux NFS server (nfsd, nfsd4_spo_must_allow)Critical
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCVE-2025-40212 · Linux NFS server (nfsd, nfsd_set_fh_dentry)Critical
- Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCVE-2025-41426 · Vertiv (stack-based buffer overflow, code execution)Critical
- Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCVE-2025-46412 · Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cardsCritical
- Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CVE-2025-49825 · TeleportCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.