Authentication Bypass in HPE Orchestrator Service
CVE-2025-37184
9.8CRITICAL
What is CVE-2025-37184?
A vulnerability has been identified within the HPE Orchestrator Service that permits an unauthenticated remote attacker to bypass essential multi-factor authentication protocols. This flaw allows for the creation of an admin user account without adhering to the required multi-factor authentication steps, significantly jeopardizing the security and integrity of the system's access control mechanisms.
Affected Version(s)
EdgeConnect SD-WAN Orchestrator 9.5.0 <= 9.6.0
EdgeConnect SD-WAN Orchestrator 9.5.0 <= 9.6.0
EdgeConnect SD-WAN Orchestrator 9.4.0 <= 9.4.4
