GPU VulnDB

Database/Control plane, storage & DevOps

HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actions

CVE-2025-37101Control plane, storage & DevOpscurated

Impact

A read-only user performs administrative actions through the OneView vCenter plugin - so view-only access to vCenter becomes administrative control over HPE hardware management.

Who can reach it

Authenticated read-only user of the OV4VC plugin, with user interaction.

What to do

Apply the HPE update per HPESBGN04876. Plugin update inside vCenter; no server firmware work.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.