Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jan 28, 2026

CVE-2025-37164

High
EPSS 84.8%CISA KEV

Description

Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.

EPSS — Exploit Probability

84.8%

Higher than 99.3% of all CVEs

Required Action

https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2025-37164

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
84.8%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jan 7, 2026

Added to KEV

Jan 7, 2026

Remediation Due

Jan 28, 2026

Affected Product

Hewlett Packard Enterprise (HPE)

OneView

View all Hewlett Packard Enterprise (HPE) CVEs