Database/Control plane, storage & DevOps
HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS server
CVSS 9.8CVE-2025-37099Control plane, storage & DevOpscurated
Impact
Unauthenticated remote code execution on the Insight RS server. IRS has inbound reach to your whole HPE estate and outbound reach to HPE, so it is a high-value pivot in both directions.
Who can reach it
Unauthenticated network access to Insight RS below v7.15.0.646.
What to do
Upgrade Insight RS to 7.15.0.646. Application upgrade with restart. IRS rarely needs broad network exposure - firewall it to the devices it actually monitors.
References
Related entries
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCVE-2025-38430 · Linux NFS server (nfsd, nfsd4_spo_must_allow)Critical
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCVE-2025-40212 · Linux NFS server (nfsd, nfsd_set_fh_dentry)Critical
- Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCVE-2025-41426 · Vertiv (stack-based buffer overflow, code execution)Critical
- Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCVE-2025-46412 · Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cardsCritical
- Teleport: Remote authentication bypass in Teleport Community Edition (<=17.5.1)CVE-2025-49825 · TeleportCritical
- F5 BIG-IP (APM access policy): Specific malicious traffic against a virtual server with a BIG-IP APM access policyCVE-2025-53521 · F5 BIG-IP (APM access policy)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.