HPE OneView CVE-2025-37164 worth paying attention to

- Widely used enterprise management software

- HPE added a REST command, executeCommand, which requires no authentication to execute commands. Obviously, this is dumb and now patched out

- Being on OneView allows attacker to access VMware, 3PAR storage etc by design

- Expect exploitation in the wild as it's so simple

- The vulnerability (executeCommand) was introduced around 2020, feels like a vulndoor

Shodan dork: product:"HPE OneView"

0

If you have a fediverse account, you can quote this note from your own instance. Search https://cyberplace.social/users/GossiTheDog/statuses/115745701289876342 on your instance and quote it. (Note that quoting is not supported in Mastodon.)