Aruba Security Update – 22 December 2025

HPE Aruba has released a security update to address a critical vulnerability affecting HPE OneView software versions before 11.00.

The addressed vulnerability could allow the unauthenticated remote attacker to execute arbitrary code and gain access to the affected system.

HPE OneView Remote Code Execution Vulnerability (CVE-2025-37164):

  • CVSS: 10.0
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2025-37164

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Aruba Security Advisory

References