Database/Control plane, storage & DevOps
HPE Insight Remote Support (unauthenticated denial of service): An unauthenticated attacker takes Insight RS down
CVSS 7.5CVE-2025-37097Control plane, storage & DevOpscurated
Impact
An unauthenticated attacker takes Insight RS down, blinding your support and monitoring path for the HPE estate.
Who can reach it
Unauthenticated network access below v7.15.0.646.
What to do
Upgrade Insight RS to 7.15.0.646.
References
Related entries
- HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS serverCVE-2025-37098 · HPE Insight Remote Support (path traversal)High
- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationCVE-2025-5777 · Citrix NetScaler ADC/GatewayHigh
- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeCVE-2025-58187 · Go crypto/x509 (Tailscale, Go infra)High
- Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callersCVE-2025-62188 · Apache DolphinScheduler 3.1.x (exposed Spring Boot management endpoints)High
- Apache Airflow: pre-3.2 deployments lack the isolation guarantees operators assumed, per clarified security modelCVE-2025-66236 · Apache Airflow (workload isolation and JWT token authentication, deployments before 3.2.0)High
- IBM Storage Scale GUI (hardcoded inter-node token): A hardcoded token in the Storage Scale GUI source, usedCVE-2026-13460 · IBM Storage Scale GUI (hardcoded inter-node token)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.