Home › Hewlett Packard Enterprise (HPE)
CVE-2025-37164: Hewlett Packard Enterprise (HPE) OneView
EPSS90.1%No. 461 of 1739 in KEV
CVE year2025~1 yrs before listing
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | Hewlett Packard Enterprise (HPE) |
| Product | OneView |
| Name | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability |
| Added to KEV | 2026-01-07 |
| US federal due date | 2026-01-28 |
| Ransomware use | Unknown |
| CWE | CWE-94 |
CISA description
Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Hewlett Packard Enterprise (HPE) OneView vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07.