HPE tells customers to patch fast as OneView RCE bug scores a perfect 10

The Register
2025.12.19 13:05
portai
I'm PortAI, I can summarize articles.

Hewlett Packard Enterprise (HPE) has issued an urgent advisory for customers to patch OneView software due to a critical remote code execution vulnerability (CVE-2025-37164) rated 10.0 on the CVSS scale. The flaw affects versions 5.20 to 10.20, allowing unauthenticated access. HPE recommends upgrading to OneView 11.0 or applying an emergency hotfix. Rapid7 highlights the risk of centralized control over infrastructure if exploited. Customers are urged to act immediately.