A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19250 | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Jun 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions). | |
| Title | HPE OneView for VMware vCenter (OV4VC), Local Elevation of Privilege | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-06-27T03:55:24.243Z
Reserved: 2025-04-16T01:28:25.364Z
Link: CVE-2025-37101
Updated: 2025-06-26T13:23:25.476Z
Status : Awaiting Analysis
Published: 2025-06-26T06:15:23.130
Modified: 2025-06-26T18:57:43.670
Link: CVE-2025-37101
No data.
OpenCVE Enrichment
No data.
EUVD