A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23308 | A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe telco Network Function Virtual Orchestrator |
|
| Vendors & Products |
Hpe
Hpe telco Network Function Virtual Orchestrator |
Thu, 31 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. | |
| Title | Hard-Coded Encryption Keys found in System | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-07-31T20:01:12.230Z
Reserved: 2025-04-16T01:28:25.365Z
Link: CVE-2025-37112
No data.
Status : Awaiting Analysis
Published: 2025-07-31T20:15:32.990
Modified: 2025-08-04T15:06:36.623
Link: CVE-2025-37112
No data.
OpenCVE Enrichment
Updated: 2025-08-04T09:00:50Z
Weaknesses
EUVD