A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe telco Network Function Virtual Orchestrator |
|
| Vendors & Products |
Hpe
Hpe telco Network Function Virtual Orchestrator |
Thu, 31 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Jul 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information. | |
| Title | Hard-Coded Authentication Keys found in System | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published: 2025-07-31T19:41:54.593Z
Updated: 2025-07-31T20:02:46.356Z
Reserved: 2025-04-16T01:28:25.365Z
Link: CVE-2025-37111
Updated: 2025-07-31T20:02:38.898Z
Status : Awaiting Analysis
Published: 2025-07-31T20:15:32.823
Modified: 2025-08-04T15:06:36.623
Link: CVE-2025-37111
No data.