κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / HPE Insight Remote Support Vulnerability Let Attackers Execute Remote Code
άμυνα
.

HPE Insight Remote Support Vulnerability Let Attackers Execute Remote Code

06/06/2025

Multiple severe security vulnerabilities in HPE Insight Remote Support (IRS) platform that could allow attackers to execute remote code, traverse directories, and access sensitive information. 

The vulnerabilities affect versions prior to 7.15.0.646 and pose significant risks to enterprise infrastructure management systems.

Critical HPE IRS Remote Execution Vulnerability 

This critical vulnerability CVE-2025-37099 scored 9.8 on the CVSS v3.1 scale uses the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-based exploitation requiring no privileges or user interaction. 

Attackers can exploit this flaw to execute arbitrary commands on unpatched IRS installations, potentially compromising entire enterprise monitoring systems.

The vulnerability stems from improper input validation in IRS’s data processing routines, allowing malicious payloads to bypass security checks. Successful exploitation enables attackers to:

  • Deploy ransomware or cryptominers across connected systems.
  • Manipulate monitoring data to hide malicious activities.
  • Establish persistent backdoors for lateral movement within networks.

HPE confirms this vulnerability was reported through Trend Micro’s Zero Day Initiative , highlighting its appeal to advanced threat actors.

Medium-Severity HPE IRS Flaws

CVE-2025-37097 is a Directory Traversal flaw (CVSS 7.5) that enables attackers to access files outside the IRS’s restricted directories. While rated 7.5, it serves as a critical enabler for follow-on attacks by exposing:

  • Configuration files containing credentials for connected devices.
  • TLS certificates are used for secure communications.
  • System logs reveal network architecture details.

CVE-2025-37098 is a Privileged Information Disclosure (CVSS 6.5). This medium-severity vulnerability allows authenticated users with low privileges to access sensitive system information. The flaw exposes:

  • API keys for integrated HPE OneView systems.
  • Hardware inventory details of managed servers.
  • Firmware versions of connected storage arrays.

While requiring valid credentials, this vulnerability becomes particularly dangerous in compromised environments where attackers have obtained basic access through phishing or credential-stuffing attacks.

CVEsAffected ProductsImpactExploit PrerequisitesCVSS 3.1 ScoreCVE-2025-37099HPE Insight Remote Support <7.15.0.646Remote Code Execution (RCE)Network access; No authentication9.8 (Critical)CVE-2025-37097HPE Insight Remote Support <7.15.0.646Directory TraversalNetwork access; No authentication7.5 (High)CVE-2025-37098HPE Insight Remote Support <7.15.0.646Information DisclosureNetwork access; Low privileges6.5 (Medium)

Remediation 

HPE has released Insight Remote Support version 7.15.0.646 to address all identified vulnerabilities. 

The company strongly recommends an immediate upgrade to this version or later releases to mitigate security risks. Organizations should prioritize patching efforts based on the critical CVSS 9.8 rating of CVE-2025-37099.

The embedded software management capability provides automated patch deployment through Administrator Settings > Software Updates. 

HPE recommends enabling the “Automatically Download and Install” option from the Automatic Update Level dropdown to ensure continuous security updates.

System administrators should implement additional security measures, including network segmentation, access controls, and monitoring for suspicious activities targeting HPE Insight Remote Support installations. 

Regular security assessments and adherence to patch management policies remain essential for maintaining secure enterprise environments.

Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests
Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

Our favorite third-party Windows customization tool now lets you clean your storage better

If you want to take control over Windows' features, you could do a lot worse than giving Wintoys a try. It's a cool little third-party suite of stuff you can check out, and we recently named it something everyone should be using. Source: xda-developers.com … [Read More...]

One of the best ways to evade Windows 11's system requirements now lets you control when Windows updates

Windows 10's end-of-life date is fast approaching, and in response, the apps designed to help people transition to Windows 11 are undergoing a flurry of updates to handle the expected influx of users better. Currently, two apps help users bypass Windows 11's system requirements: Rufus (which recently received a dark mode update) and Flyoobe (formerly Flyby11). Source: xda-developers.com … [Read More...]

Heidi Health raises $65M Series B led by Steve Cohen’s Point72

Dr. Tom Kelly is a trauma surgeon, and everywhere, he sees doctors drowning in administrative work. He wanted change, so he set out to build it.  “We wanted to build an AI care partner that would stand alongside clinicians and take care of the admin so that individual providers, like me, can feel empowered to deliver the care which we dedicated our lives to,” he told … [Read More...]

OnePlus 15 to Reportedly Carry the Largest Battery on a OnePlus Smartphone

OnePlus 15 launch appears to be around the corner, after the company confirmed that the smartphone will make its debut in China in October. Meanwhile, a new report claims that the OnePlus 13 successor will be backed by the largest battery ever seen on a OnePlus smartphone. Alongside, it is also expected to support wireless charging. The new details arrive just days after a tipster claimed that the … [Read More...]

3 reasons why Perplexity’s Comet has become my go-to browser

There’s no shortage of browsers nowadays, and a new one seems to pop up every few days. And though some of the browsers that launch quietly fade away and are eventually forgotten, every so often one comes along that manages to take over the internet. Source: xda-developers.com … [Read More...]

3 signs that you need a new CPU instead of a GPU

When you experience lower average frame rates or FPS drops, it's easy to assume that your graphics card is the culprit. After all, it's the main component that drives the visuals while you're gaming. However, the issue is that your GPU isn't always the primary cause of all your FPS issues. Although it does most of the heavy lifting in graphically demanding workloads, your CPU plays an equally … [Read More...]

The 3 PlayStation Plus games announced at State of Play you have to download to your PS5

PlayStation has been building up the catalog of classics and new titles available to players through the PlayStation Plus game catalog. With the September 2025 State of Play presentation, that catalog of titles for PS5 owners is continuing to get larger, offering a variety of games to play on the console. Unlike previous showings of State of Play, some highly requested and classic games are making … [Read More...]

5 productivity apps that made my NAS more useful than Google Workspace

Google Workspace is the industry default productivity suite, and rightly so — it’s fast, reliable, has excellent integrations, and offers handy collaboration features. However, it is just another subscription added to your credit card, which starts to bother you, especially if your team size is growing. Source: xda-developers.com … [Read More...]

6 tiny self-hosting tools that save me hours every week

If you are like me, you love the idea of self-hosting, but hate the thought of endless configuration and maintenance. The truth is, self-hosting doesn’t have to be a major time sink – it can actually be a massive time saver. I have spent months testing and refining my setup, and in the process, I have found tiny set-it-and-forget-it tools that work tirelessly in the background. Source: … [Read More...]

4 video game franchises that have lost their identity

Every successful game franchise has something that makes it unique: a style, a story, or a gameplay mechanic that players fall in love with. But when a series strays too far from its roots, that identity starts to fade. Here are four big franchises that lost touch with what made them special. Source: xda-developers.com … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Our favorite third-party Windows customization tool now lets you clean your storage better
  • One of the best ways to evade Windows 11's system requirements now lets you control when Windows updates
  • Heidi Health raises $65M Series B led by Steve Cohen’s Point72
  • OnePlus 15 to Reportedly Carry the Largest Battery on a OnePlus Smartphone
  • 3 reasons why Perplexity’s Comet has become my go-to browser

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023