
CVE-2025-37093 – Hewlett Packard Enterprise StoreOnce VSA Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2025-37093
02 Jun 2025 — An authentication bypass vulnerability exists in HPE StoreOnce Software. This vulnerability allows remote attackers to bypass authentication on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the machineAccountCheck method. The issue results from improper implementation of an authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on t... • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US • CWE-287: Improper Authentication •

CVE-2025-37094 – Hewlett Packard Enterprise StoreOnce VSA deletePackages Directory Traversal Arbitrary File Deletion Vulnerability
https://notcve.org/view.php?id=CVE-2025-37094
02 Jun 2025 — A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the deletePackages method. The issue results from the lack of proper validation of a user-supplied pat... • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2025-37095 – Hewlett Packard Enterprise StoreOnce VSA getServerPayload Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2025-37095
02 Jun 2025 — A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the getServerPayload method. The issue results from the lack of proper validation of a user-sup... • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2025-37096 – Hewlett Packard Enterprise StoreOnce VSA getServerCertificate Command Injection Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-37096
02 Jun 2025 — A command injection remote code execution vulnerability exists in HPE StoreOnce Software. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise StoreOnce VSA. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the getServerCertificate method. The issue results from the lack of proper validation of a user-supplied s... • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2025-37087
https://notcve.org/view.php?id=CVE-2025-37087
22 Apr 2025 — A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. Una vulnerabilidad en el servicio cmdb del HPE Performance Cluster Manager (HPCM) podría permitir que un atacante obtenga acceso a un archivo arbitrario en el host del servidor. • https://support.hpe.com/hpesc/docDisplay?docLocale=en_US&docId=a00146087en_us • CWE-862: Missing Authorization •

CVE-2025-27084 – Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal (CP) of an AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-based Management Interface
https://notcve.org/view.php?id=CVE-2025-27084
08 Apr 2025 — A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface. • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-27085 – Arbitrary File Download Vulnerabilities in Web-Based Management Interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor
https://notcve.org/view.php?id=CVE-2025-27085
08 Apr 2025 — Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2025-27083 – Authenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
https://notcve.org/view.php?id=CVE-2025-27083
08 Apr 2025 — Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system. • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2025-27082 – Authenticated Remote Code Execution Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write
https://notcve.org/view.php?id=CVE-2025-27082
08 Apr 2025 — Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system. • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04845en_us&docLocale=en_US • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2025-27079 – Arbitrary File Creation vulnerability allows for Authenticated Remote Code Execution in CLI Interface
https://notcve.org/view.php?id=CVE-2025-27079
08 Apr 2025 — A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise. • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04844en_us&docLocale=en_US • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •