Tech

HPE flags critical StoreOnce auth bypass, users should update now

Share
Share


  • HPE patches eight flaws in StoreOnce platform
  • Among the flaws is a critical severity authentication bypass
  • There are no workarounds and users are advised to patch up

Hewlett Packard Enterprise (HPE) has revealed patches for a number of dangerous flaws affecting its data backup and recovery solution, StoreOnce, including a critical-severity bug which allows threat actors to gain full access to the vulnerable system without user interaction.

The bug is tracked as CVE-2025-37093, and is described as an authentication bypass flaw stemming from improper authentication handling. It has a severity score of 9.8/10 (critical) and could potentially be abused to compromise system integrity, allow threat actors to access sensitive data, and lead to different disruptions and availability issues.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *