← back
CVE-2025-37110

Sensitive Credential Information stored insecurely in System Database

CVSS 6 MEDIUMEPSS 0.1%CWE-922
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
31 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →