By Carly Page
Publication Date: 2025-12-19 13:03:00
Hewlett Packard Enterprise has told customers to stop what they are doing and patch OneView after admitting that a maximum severity bug could allow attackers to execute code on the management platform without even a login prompt.
The vulnerability, tracked as CVE-2025-37164 and with a maximum rating of 10.0 on the CVSS scale, affects HPE OneView versions 5.20 through 10.20 and allows unauthenticated remote code execution. according to a notice published by the company this week. OneView sits at the heart of many enterprise environments, acting as a central control plane for servers, firmware, storage, and lifecycle management.
“A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView software,” HPE said in its advisory. “This vulnerability could be exploited, allowing an unauthenticated remote user to perform remote code execution.”
HPE said the issue was reported by security…


