By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Tech News

Hewlett Packard Enterprise warns of critical StoreOnce auth bypass

By admin 3 Min Read
Share
SHARE

Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution.

Among the flaws fixed this time is a critical severity (CVSS v3.1 score: 9.8) authentication bypass vulnerability tracked under CVE-2025-37093, three remote code execution bugs, two directory traversal problems, and a server-side request forgery issue.

The flaws impact all versions of the HPE StoreOnce Software before v4.3.11, which is now the recommended upgrade version.

Here’s the complete list of the eight vulnerabilities HPE fixed in version 4.3.11:

  • CVE-2025-37089 – Remote Code Execution
  • CVE-2025-37090 – Server-Side Request Forgery
  • CVE-2025-37091 – Remote Code Execution
  • CVE-2025-37092 – Remote Code Execution
  • CVE-2025-37093 – Authentication Bypass
  • CVE-2025-37094 – Directory Traversal Arbitrary File Deletion
  • CVE-2025-37095 – Directory Traversal Information Disclosure
  • CVE-2025-37096 – Remote Code Execution

Not many details were disclosed about the flaws this time.

However, Zero Day Initiative (ZDI), which discovered them, mentions that CVE-2025-37093 exists within the implementation of the machineAccountCheck method, resulting from improper implementation of an authentication algorithm.

Although CVE-2025-37093 is the only vulnerability rated as critical, others still carry significant risks even if they are typically categorized lower in the severity rating.

The ZDI explains that the authentication bypass problem is the key to unlocking the potential in all other flaws, so their risk isn’t isolated.

The examples of CVE-2025-3794 and CVE-2025-37095, two medium-severity file deletion and information disclosure flaws, show that exploitation is practically easier than what’s reflected in the score.

“This vulnerability allows remote attackers to disclose sensitive information on affected installations of Hewlett Packard Enterprise StoreOnce VSA,” explains ZDI.

“Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.”

Notably, the flaws were discovered and reported to HPE in October 2024, with seven full months having passed until fixes finally became available to customers. Still, there are no reports of active exploitation.

HPE StoreOnce is typically used for backup and recovery in large enterprises, data centers, cloud service providers, and generally, organizations handling big data or large virtualized environments.

StoreOnce integrates with backup software like HPE Data Protector, Veeam, Commvault, and Veritas NetBackup, ensuring business continuity and effective backup management.

That being said, administrators of potentially impacted environments must take immediate action and apply the available security updates to close the gaps.

HPE has listed no mitigations or workarounds for the eight flaws in the bulletin, so upgrading is the recommended solution.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

You Might Also Like

Best Fitness Tracker 2026: Fitbits, Bands & Hybrids

Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That

Critical Fortinet Forticlient EMS flaw now exploited in attacks

21 organisations currently adding to their engineering teams

M5 Ultra Mac Studio Leaks: 8K Video and GPU Benchmarks

TAGGED: Authentication Bypass, Backup, Hewlett Packard Enterprise, HPE, HPE StoreOnce, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article How Much Are UFC 316 Tickets For Merab Dvalishvili vs Sean O’Malley 2 At The Prudential Center In Newark?
Next Article IDF says roads to Gaza aid centres are 'combat zones' as sites close for day
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Dimension 20 Is Finally Doing A Vampire: The Masquerade Campaign And I Am So Stoked
Gaming News
Brush up: How to plan a creative holiday in Europe
Travel
Best Fitness Tracker 2026: Fitbits, Bands & Hybrids
Tech News
Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That
Tech News
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Tech News
Is it time Premier League Darts introduced a reserve player for withdrawals?
Sports
Jefferies screams buy on HDFC Bank, says valuation attractive after 25% dip
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Dimension 20 Is Finally Doing A Vampire: The Masquerade Campaign And I Am So Stoked

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Dimension 20 Is Finally Doing A Vampire: The Masquerade Campaign And I Am So Stoked
March 30, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?