« Back to list

HPE

HPE Oneview: vulnerabilities and CVEs

HPE Oneview has 6 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs6
Last 12 months4
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-37164Critical (9.8)90%⚠ Active exploitationDec 16, 2025
A remote code execution issue exists in HPE OneView.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76720Medium (4.3)0.17%—Sep 29, 2026
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
CVE-2026-76719High (8.2)0.18%—Sep 29, 2026
A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
CVE-2026-76718High (8.2)0.24%—Sep 29, 2026
A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.
CVE-2025-37164Critical (9.8)90%⚠ Active exploitationDec 16, 2025
A remote code execution issue exists in HPE OneView.
CVE-2024-42508Medium (5.5)0.16%—Oct 18, 2024
This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.
CVE-2023-30912Critical (9.8)1.2%—Oct 25, 2023
A remote code execution issue exists in HPE OneView.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1189 Drive-by Compromise2
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1190 Exploit Public-Facing Application1
  5. T1203 Exploitation for Client Execution1
  6. T1204.001 Malicious Link1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by HPE