
Detection for CVE-2025-37164
A remote code execution issue exists in HPE OneView.
This template matches on the OneView title tag, extracts the version from the JavaScript artifactVersion variable, and flags instances running versions below 11.00 as potentially vulnerable.
NOTE that instances flagged by this template are possibly vulnerable as the detection method cannot determine whether the Z7550-98077 security hotfix has been applied to versions 5.20-10.20 - only upgrading to version 11.00+ can be reliably verified as patched.
nuclei -u <ip|fqdn> -t template.yaml
Or if you would like to scan a list of hosts, execute:
nuclei -l <list.txt> -t template.yaml
Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
This project is licensed under the MIT License.
If you have any questions about this vulnerability detection script please reach out to me via Signal.
If you would like to connect, I am mostly active on Twitter/X and LinkedIn.