Vertical Privilege Escalation in HPE OneView for VMware vCenter
CVE-2025-37101

8.7HIGH

Key Information:

Vendor

HP

Vendor
CVE Published:
26 June 2025

What is CVE-2025-37101?

A security vulnerability has been identified in HPE OneView for VMware vCenter, which could potentially enable an attacker with read-only privileges to exploit the system. This flaw allows the operator to perform administrative actions, thereby compromising the integrity and security of the affected environment. Addressing this vulnerability is critical to maintaining secure operations and preventing unauthorized access to sensitive functionality.

Affected Version(s)

HPE OneView for VMware vCenter Windows Prior to v11.7

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-37101 : Vertical Privilege Escalation in HPE OneView for VMware vCenter