GPU VulnDB

Database/Control plane, storage & DevOps

HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope change

CVE-2025-37164Control plane, storage & DevOpsKnown exploitedcurated

Impact

Unauthenticated remote code execution on OneView with scope change - a perfect-10 finding. OneView is HPE's fleet management plane: it holds iLO credentials, drives firmware deployment and owns server profiles, so RCE there is effectively root on every managed server. A public Metasploit module exists.

Who can reach it

Anyone who can reach the OneView web interface. No credentials.

What to do

Patch OneView immediately per HPESBGN04985 - this is the single highest-priority item in this sweep. Appliance update with a service restart. Assume compromise if OneView has been network-reachable and unpatched: rotate every iLO and service-account credential it holds, and review deployed firmware for tampering.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.