GPU VulnDB

Database/Control plane, storage & DevOps

HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining

CVE-2025-37093Control plane, storage & DevOpscurated

Impact

Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining full control of the backup appliance. Backup systems hold copies of everything and are a primary ransomware target - this is the bug that makes your recovery path attackable.

Who can reach it

Network access to the StoreOnce management interface. No credentials.

What to do

Upgrade StoreOnce Software per HPESBST04847 as a priority. Appliance upgrade with a service window. Verify backup immutability/retention-lock settings while you are there - authentication bypass plus mutable backups is the ransomware worst case.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.