Full Report
Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution. [...]
Analysis Summary
# Vulnerability: HPE StoreOnce Authentication Bypass and Data Disclosure Flaws
## CVE Details
- CVE ID: Not fully specified for all flaws, but CVE-2025-3794 and CVE-2025-37095 are mentioned.
- CVSS Score: Medium severity (for the mentioned CVEs)
- CWE: Not explicitly stated, but likely related to Authentication Bypass (CWE-287) or Improper Access Control.
## Affected Systems
- Products: Hewlett Packard Enterprise (HPE) StoreOnce VSA
- Versions: Unspecified in detail, but all versions before the application of patches listed in the vendor bulletin are considered vulnerable.
- Configurations: Environments using HPE StoreOnce for backup and recovery (integrates with Veeam, Commvault, Veritas NetBackup, etc.).
## Vulnerability Description
The advisory covers eight vulnerabilities impacting HPE StoreOnce, including two medium-severity flaws: CVE-2025-3794 (file deletion) and CVE-2025-37095 (information disclosure). The authentication bypass flaw is particularly critical because it allows a remote attacker to **bypass the existing authentication mechanism** and gain unauthorized access to the system. Specifically, CVE-2025-37095 allows remote attackers to disclose sensitive information on affected installations of HPE StoreOnce VSA, despite being technically rated as 'authentication required'.
## Exploitation
- Status: No reports of *active* exploitation in the wild, but PoC details are implied by the ZDI advisory context.
- Complexity: Low/Medium (Since authentication can be bypassed, exploitation difficulty is likely reduced).
- Attack Vector: Network (Remote attackers are mentioned).
## Impact
- Confidentiality: High (Information Disclosure via bypass vulnerability).
- Integrity: Moderate (File deletion vulnerability mentioned).
- Availability: Unknown/Moderate (Depending on the specific flaw exploited).
## Remediation
### Patches
- **Action Required:** Administrators must apply the security updates released by HPE to address the eight identified flaws. (Specific patch versions are not detailed in this summary but are available from HPE).
### Workarounds
- HPE has listed **no official mitigations or workarounds** for the eight flaws. Upgrading is the mandatory recommended solution.
## Detection
- **Indicators of Compromise:** Unexplained sensitive data exposure or unauthorized file deletion related to StoreOnce operations, especially following failed/unauthenticated access attempts.
- **Detection Methods and Tools:** Requires monitoring appliance logs for successful or attempted access that circumvents standard authentication protocols, correlated with monitoring for file deletion activities.
## References
- Vendor Advisories: Refer to the relevant HPE security bulletin regarding StoreOnce updates.
- Relevant links:
- ZDI Advisory: hxxps://www[.]zerodayinitiative[.]com/advisories/ZDI-25-317/