CVE-2025-37111

MEDIUM

HPE Telco NFVO - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.

Scores

CVSS v3 6.0
EPSS 0.0002
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
Hewlett Packard Enterprise/HPE Telco Network Function Virtual Orchestrator 7.0.0 - 7.3.0
Published Jul 31, 2025
Tracked Since Feb 18, 2026