Database/Control plane, storage & DevOps
HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS server
CVE-2025-37099Control plane, storage & DevOpscurated
Impact
Unauthenticated remote code execution on the Insight RS server. IRS has inbound reach to your whole HPE estate and outbound reach to HPE, so it is a high-value pivot in both directions.
Who can reach it
Unauthenticated network access to Insight RS below v7.15.0.646.
What to do
Upgrade Insight RS to 7.15.0.646. Application upgrade with restart. IRS rarely needs broad network exposure - firewall it to the devices it actually monitors.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.