Database/Control plane, storage & DevOps

HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope change
Impact
Unauthenticated remote code execution on OneView with scope change - a perfect-10 finding. OneView is HPE's fleet management plane: it holds iLO credentials, drives firmware deployment and owns server profiles, so RCE there is effectively root on every managed server. A public Metasploit module exists.
Who can reach it
Anyone who can reach the OneView web interface. No credentials.
What to do
Patch OneView immediately per HPESBGN04985 - this is the single highest-priority item in this sweep. Appliance update with a service restart. Assume compromise if OneView has been network-reachable and unpatched: rotate every iLO and service-account credential it holds, and review deployed firmware for tampering.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.