Home icon Chevron Categories Chevron Blog Chevron News Chevron

HPE Issues Critical Security Fixes for StoreOnce Backup Systems

HPE Issues Critical Security Fixes for StoreOnce Backup Systems

June 04, 2025


Hewlett Packard Enterprise (HPE) has rolled out urgent security patches to fix eight separate vulnerabilities in its StoreOnce data backup and deduplication platform. These flaws, if left unaddressed, could enable attackers to bypass authentication measures and execute remote code on affected systems.

According to HPE’s official advisory, the vulnerabilities open the door to various attack vectors, including remote code execution (RCE), information leakage, server-side request forgery (SSRF), unauthorized access, file deletion, and directory traversal attacks.

One of the most serious issues, tracked as CVE-2025-37093, holds a critical severity rating of 9.8 on the CVSS scale. This flaw, found in all versions prior to 4.3.11, allows attackers to bypass authentication entirely. Reported on October 31, 2024, the bug was discovered by an anonymous researcher and shared via the Zero Day Initiative (ZDI).

ZDI explained the root of the vulnerability lies in a faulty implementation of the machineAccountCheck method, which fails to correctly validate authentication. If exploited, it can be used by remote attackers to gain unauthorized access and potentially chain with other vulnerabilities to perform further malicious actions like executing code, stealing data, or deleting files — all with root-level privileges.

The list of addressed vulnerabilities includes:

  • CVE-2025-37089 – Remote Code Execution

  • CVE-2025-37090 – Server-Side Request Forgery

  • CVE-2025-37091 – Remote Code Execution

  • CVE-2025-37092 – Remote Code Execution

  • CVE-2025-37093 – Authentication Bypass

  • CVE-2025-37094 – Arbitrary File Deletion via Directory Traversal

  • CVE-2025-37095 – Information Disclosure via Directory Traversal

  • CVE-2025-37096 – Remote Code Execution

In addition, HPE also released updates for other critical vulnerabilities in its Telco Service Orchestrator (CVE-2025-31651) and OneView management software (CVE-2024-38475 and CVE-2024-38476), both scoring 9.8, stemming from previously known issues in Apache Tomcat and Apache HTTP Server components.

At present, no signs of active exploitation have been reported. However, HPE strongly advises all users to apply the latest security updates as soon as possible to minimise risk.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news


Did you like the post? Share it in your media

Latest Articles

Featured

Automated Pentest Says You Are Secure? Security Experts Warn That Is Not the Full Story 

June 10, 2026 · Chetna Sehgal

Many organizations today rely on automated penetration-testing tools to evaluate their cybersecur...

Read More >
Featured

Anthropic Launches Claude Fable 5: Powerful New AI Model Arrives With Built-In Cybersecurity Safeguards 

June 10, 2026 · Chetna Sehgal

Anthropic has officially introduced Claude Fable 5, describing it as the most powerful AI model t...

Read More >
Featured

The Autonomous SOC: Are AI Analysts Ready to Replace Tier-1 Security Operations?

June 09, 2026 · Chetna Sehgal

The numbers are familiar to anyone who has spent time inside a security operations center. Hundre...

Read More >
Featured

WhatsApp Uncovers New NSO Group-Linked Spearphishing Campaign Despite Court Ban 

June 09, 2026 · Chetna Sehgal

WhatsApp has revealed that it recently disrupted a new wave of spearphishing attempts linked to t...

Read More >
Featured

LiteLLM Vulnerability Under Active Attack: Flaw Chain Enables Unauthenticated Remote Code Execution

June 09, 2026 · Chetna Sehgal

A serious security flaw in LiteLLM, tracked as CVE-2026-42271, is now being actively exploited by...

Read More >
Featured

UNC3753 Turns Phone Calls Into Data Theft: Inside the Latest U.S. Extortion Campaign

June 08, 2026 · Chetna Sehgal

Cybersecurity researchers have uncovered a large-scale data theft and extortion campaign carried ...

Read More >
Newsletter line