newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: HPE issues a security patch for StoreOnce bugs that allow remote authentication bypass
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > HPE issues a security patch for StoreOnce bugs that allow remote authentication bypass
Technology

HPE issues a security patch for StoreOnce bugs that allow remote authentication bypass

June 4, 2025 2 Min Read
Share
HPE issues a security patch for StoreOnce bugs that allow remote authentication bypass
SHARE

Hewlett Packard Enterprise (HPE) has released security updates to address eight vulnerabilities in StoreOnce data backup and deduplication solutions, potentially resulting in authentication bypassing and remote code execution.

“These vulnerabilities could be exploited remotely to allow vulnerabilities in remote code execution, information disclosure, server-side request forgery, authentication bypass, arbitrary file deletion, and directory traversal information,” HPE said in its advisory.

This includes fixes for critical security flaws tracked as CVE-2025-37093, which is rated 9.8 on the CVSS scoring system. It was described as an authentication bypass bug that affects all versions of the software prior to 4.3.11. The vulnerability, along with the rest, was reported to the vendor on October 31, 2024.

According to the Zero Day Initiative (ZDI), anonymous researchers have found and reported the shortcomings, and the issue is rooted in the implementation of the MachineaCcountCheck method.

“This issue is caused by an inappropriate implementation of the authentication algorithm,” ZDI said. “Attackators can exploit this vulnerability to bypass authentication on the system.”

The successful exploitation of CVE-2025-37093 allows remote attackers to bypass authentication on affected installations. What makes the vulnerability even more serious is that it can be chained with the remaining flaws to achieve code execution, information disclosure, and arbitrary file deletion in the context of the root –

  • CVE-2025-37089-Remote code execution
  • CVE-2025-37090-Server-Side Request Forged
  • CVE-2025-37091-Remote code execution
  • CVE-2025-37092-Run Remote Code
  • CVE-2025-37093-Authentication bypass
  • CVE-2025-37094-Directory Traversal Delete any file
  • CVE-2025-37095-Directory Traversal Information Disclosure
  • CVE-2025-37096-Run Remote Code

HPE also ships patches that address multiple severity defects for HPE Telco Service Orchestrator (CVE-2025-31651, CVSS Score: 9.8) and Oneview (CVE-2024-38475, CVE-2024-38476, CVSS Scores Inn) postponed: 9.8SS scores, as HPE also shipped patches that address multiple severity defects for CVE-2024-38475, CVE-2024-38476 until the advent of 9.8SS scores. Apache HTTP server.

See also  Transforming LLM Performance: How AWS's Automated Evaluation Framework Leads How

There are no reports of aggressive exploitation, but it is essential that users apply the latest updates for optimal protection.

Share This Article
Facebook Twitter Copy Link
Previous Article Experts Explain: Can Melatonin Improve Sleep on a Flight? Experts Explain: Can Melatonin Improve Sleep on a Flight?
Next Article DeepSeek-V3 unveiled: How hardware-enabled AI designs reduce costs and increase performance DeepSeek-V3 unveiled: How hardware-enabled AI designs reduce costs and increase performance
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

New research uses attachment theory to decipher relationships with humans
Technology

New research uses attachment theory to decipher relationships with humans

9 Min Read
New Linux flaws allow password hash theft via core dumps in Ubuntu, Rhel, Fedora
Technology

New Linux flaws allow password hash theft via core dumps in Ubuntu, Rhel, Fedora

4 Min Read
Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI
Technology

Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI

3 Min Read
Google Chrome implements distrust and issues over two certificate authorities over compliance
Technology

Google Chrome implements distrust and issues over two certificate authorities over compliance

3 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?