Cyber Posture

CVE-2025-37164

CriticalCISA KEVActive ExploitationPublic PoC

Published: 16 December 2025

Published
16 December 2025
Modified
08 January 2026
KEV Added
07 January 2026
Patch
CVSS Score 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.8416 99.3th percentile
Risk Priority 90 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-37164 is a remote code execution vulnerability affecting HPE OneView, stemming from a CWE-94 code injection flaw. Published on 2025-12-16, it carries a maximum CVSS v3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating critical severity due to its potential for complete system compromise.

Unauthenticated attackers can exploit this vulnerability remotely over the network with low complexity and no user interaction required. Successful exploitation allows arbitrary code execution on the affected HPE OneView instance, granting high-impact confidentiality, integrity, and availability violations, including scope expansion to other system components.

HPE has issued a security bulletin (hpesbgn04985en_us) detailing the vulnerability, available at support.hpe.com. A Metasploit module for exploitation exists at github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb. Practitioners should consult these advisories for patch availability and mitigation steps.

The vulnerability appears in the CISA Known Exploited Vulnerabilities Catalog, signaling real-world exploitation activity.

Details

CWE(s)
CWE-94
KEV Date Added
07 January 2026

Affected Products

hpe
oneview
≤ 10.20.00

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The vulnerability is a critical unauthenticated remote code execution in HPE OneView, a public-facing management application, directly enabling exploitation of public-facing applications.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References