By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Tech News

Hewlett Packard Enterprise warns of critical StoreOnce auth bypass

By admin 3 Min Read
Share
SHARE

Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution.

Among the flaws fixed this time is a critical severity (CVSS v3.1 score: 9.8) authentication bypass vulnerability tracked under CVE-2025-37093, three remote code execution bugs, two directory traversal problems, and a server-side request forgery issue.

The flaws impact all versions of the HPE StoreOnce Software before v4.3.11, which is now the recommended upgrade version.

Here’s the complete list of the eight vulnerabilities HPE fixed in version 4.3.11:

  • CVE-2025-37089 – Remote Code Execution
  • CVE-2025-37090 – Server-Side Request Forgery
  • CVE-2025-37091 – Remote Code Execution
  • CVE-2025-37092 – Remote Code Execution
  • CVE-2025-37093 – Authentication Bypass
  • CVE-2025-37094 – Directory Traversal Arbitrary File Deletion
  • CVE-2025-37095 – Directory Traversal Information Disclosure
  • CVE-2025-37096 – Remote Code Execution

Not many details were disclosed about the flaws this time.

However, Zero Day Initiative (ZDI), which discovered them, mentions that CVE-2025-37093 exists within the implementation of the machineAccountCheck method, resulting from improper implementation of an authentication algorithm.

Although CVE-2025-37093 is the only vulnerability rated as critical, others still carry significant risks even if they are typically categorized lower in the severity rating.

The ZDI explains that the authentication bypass problem is the key to unlocking the potential in all other flaws, so their risk isn’t isolated.

The examples of CVE-2025-3794 and CVE-2025-37095, two medium-severity file deletion and information disclosure flaws, show that exploitation is practically easier than what’s reflected in the score.

“This vulnerability allows remote attackers to disclose sensitive information on affected installations of Hewlett Packard Enterprise StoreOnce VSA,” explains ZDI.

“Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.”

Notably, the flaws were discovered and reported to HPE in October 2024, with seven full months having passed until fixes finally became available to customers. Still, there are no reports of active exploitation.

HPE StoreOnce is typically used for backup and recovery in large enterprises, data centers, cloud service providers, and generally, organizations handling big data or large virtualized environments.

StoreOnce integrates with backup software like HPE Data Protector, Veeam, Commvault, and Veritas NetBackup, ensuring business continuity and effective backup management.

That being said, administrators of potentially impacted environments must take immediate action and apply the available security updates to close the gaps.

HPE has listed no mitigations or workarounds for the eight flaws in the bulletin, so upgrading is the recommended solution.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

You Might Also Like

Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability

What are the best cities for digital nomads?

Android XR Smart Glasses Updates and News for November 2025

Google November Pixel Drop Adds 7 New Features

WIRED Roundup: Fandom in Politics, Zuckerberg’s Illegal School, and Nepal’s Discord Revolution

TAGGED: Authentication Bypass, Backup, Hewlett Packard Enterprise, HPE, HPE StoreOnce, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article How Much Are UFC 316 Tickets For Merab Dvalishvili vs Sean O’Malley 2 At The Prudential Center In Newark?
Next Article IDF says roads to Gaza aid centres are 'combat zones' as sites close for day
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

What we learned from Ursula von der Leyen’s options paper to support Ukraine
World News
Trump ‘dominates the political scene’ like no other recent U.S. president, says famed diplomat Kishore Mahbubani
Business
Lumines Arise Review – Lights Will Guide You Home
Gaming News
SEC makes no specific mention of crypto in 2026 exam priorities
Crypto
Crypto Exchanges Binance, OKX Used By Criminals To Disguise Illicit Funds, ICIJ Investigation Finds
Crypto
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability
Tech News
Fox31 parent company buys its broadcast building for $22M
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

What we learned from Ursula von der Leyen’s options paper to support Ukraine

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
What we learned from Ursula von der Leyen’s options paper to support Ukraine
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?