CVE-2025-37164

A remote code execution issue exists in HPE OneView.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hpe:oneview:*:*:*:*:*:*:*:*

History

08 Jan 2026, 16:59

Type Values Removed Values Added
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US - Vendor Advisory
References () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb - Product () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb - Exploit
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-37164 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-37164 - US Government Resource

08 Jan 2026, 00:15

Type Values Removed Values Added
References
  • {'url': 'https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn4985en_us&docLocale=en_US', 'tags': ['Permissions Required'], 'source': 'security-alert@hpe.com'}
  • () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US -

07 Jan 2026, 19:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-37164 -

31 Dec 2025, 00:29

Type Values Removed Values Added
First Time Hpe
Hpe oneview
CPE cpe:2.3:a:hpe:oneview:*:*:*:*:*:*:*:*
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn4985en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn4985en_us&docLocale=en_US - Permissions Required
References () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb - () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb - Product
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1 - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1 - Vendor Advisory

23 Dec 2025, 12:15

Type Values Removed Values Added
References
  • () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb -

18 Dec 2025, 17:15

Type Values Removed Values Added
References
  • () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1 -

16 Dec 2025, 20:15

Type Values Removed Values Added
CWE CWE-94

16 Dec 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 17:16

Updated : 2026-01-08 16:59


NVD link : CVE-2025-37164

Mitre link : CVE-2025-37164

CVE.ORG link : CVE-2025-37164


JSON object : View

Products Affected

hpe

  • oneview
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')