Out-of-Bound Reads Vulnerability in HPE ProLiant RL300 Gen11 Server UEFI Firmware
CVE-2025-37149

6MEDIUM

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
14 October 2025

What is CVE-2025-37149?

A potential out-of-bound reads vulnerability exists in the UEFI firmware of the HPE ProLiant RL300 Gen11 Server. This issue may allow an attacker to access sensitive data from memory locations that are outside the intended boundaries, potentially leading to information disclosure. Proper mitigations and updates should be applied to safeguard systems from exploitation.

Affected Version(s)

ProLiant RL300 Gen11 Server 0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-37149 : Out-of-Bound Reads Vulnerability in HPE ProLiant RL300 Gen11 Server UEFI Firmware