Cyber Security News

Multiple HPE StoreOnce Vulnerabilities Let Attackers Execute Malicious Code Remotely

Multiple security vulnerabilities in Hewlett-Packard Enterprise (HPE) StoreOnce software platform that could allow remote attackers to execute malicious code, bypass authentication mechanisms, and access sensitive enterprise data. 

The vulnerabilities affect HPE StoreOnce VSA versions prior to 4.3.11 and present significant risks to enterprise backup and storage infrastructure worldwide.

Security Flaws Impact Enterprise Storage Security

The newly identified vulnerabilities represent a comprehensive attack surface that threatens the core security of enterprise storage environments. 

The CVE-2025-37093 vulnerability represents one of the most severe security risks identified in Hewlett-Packard Enterprise’s StoreOnce backup and recovery platform. 

This authentication bypass flaw allows unauthenticated remote attackers to completely bypass security controls and gain unauthorized access to enterprise storage systems. 

With a CVSS v3.1 base score of 9.8 (Critical), this vulnerability poses existential risks to organizations relying on unpatched HPE StoreOnce deployments for data protection.

The vulnerability portfolio includes multiple remote code execution (RCE) flaws tracked as CVE-2025-37089, CVE-2025-37091, CVE-2025-37092, and CVE-2025-37096, each carrying CVSS scores of 7.2. 

These vulnerabilities exploit weaknesses in the StoreOnce software architecture, enabling authenticated attackers with high privileges to execute arbitrary code remotely on affected systems. 

The attack vector AV:N designation indicates that these exploits can be launched across network boundaries, significantly expanding the potential attack surface for malicious actors targeting enterprise storage infrastructure.

The technical composition of these vulnerabilities reveals sophisticated attack methodologies that target multiple layers of the StoreOnce software stack. 

The directory traversal vulnerabilities CVE-2025-37094 and CVE-2025-37095 exploit path manipulation weaknesses, with the former enabling arbitrary file deletion capabilities (CVSS 5.5) and the latter facilitating information disclosure attacks (CVSS 4.9). 

These vulnerabilities leverage the CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U vector notation, indicating network-accessible attacks with low complexity requirements.

The remote code execution vulnerabilities share common characteristics in their CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H vector strings, signifying high impact potential across confidentiality, integrity, and availability domains. 

The PR:H designation indicates that while high privileges are required for exploitation, successful attacks can result in complete system compromise. 

The AC:L (Attack Complexity: Low) rating suggests that these vulnerabilities can be exploited with readily available tools and techniques, making them attractive targets for both sophisticated threat actors and opportunistic attackers.

Anonymous security researchers working in collaboration with Trend Micro’s Zero Day Initiative (ZDI) discovered these vulnerabilities through coordinated research efforts. 

Mitigations

Organizations utilizing HPE StoreOnce VSA deployments must prioritize immediate remediation through software updates to version 4.3.11 or later. 

HPE has confirmed that all identified vulnerabilities have been addressed in this release, which is available through the official Hewlett Packard Enterprise Support Center download portal. 

The remediation timeline is critical, particularly given the presence of the 9.8 CVSS-rated authentication bypass vulnerability that requires no user interaction for exploitation.

System administrators should implement comprehensive vulnerability scanning procedures to identify affected StoreOnce installations within their infrastructure. 

Following established patch management policies when deploying third-party security updates alongside the StoreOnce software upgrade. 

Organizations should also review network segmentation strategies to limit potential attack vectors while implementing the necessary software updates.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago