CVE-2025-37088

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 22, 2025
Updated: Apr 25, 2025
CWE ID 362

Summary

CVE-2025-37088 is a newly identified security vulnerability affecting HPE Cray Data Virtualization Service (DVS). This issue involves race conditions and certain configurations, potentially allowing unauthorized access to local and cluster systems. If exploited, the vulnerability could result in significant security risks. HPE urges users to update their DVS installations to the latest patches to mitigate this threat. The exact details of the exploit remain unknown at this time, but it is recommended that all relevant parties take immediate action to secure their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share