Safeguard
Vulnerability Analysis

HPE OneView and Fortra GoAnywhere MFT: Two Perfect-10 Unauthenticated RCEs

Infrastructure management and managed file transfer software rarely share a vulnerability post, but both HPE OneView and Fortra GoAnywhere MFT scored a maximum CVSS 10.0 for unauthenticated RCE.

Safeguard Research Team
5 min read

Two unrelated enterprise infrastructure products — HPE OneView, used to manage physical server and network hardware, and Fortra's GoAnywhere MFT, used to move files across trust boundaries — each produced a confirmed-exploited vulnerability scoring a perfect CVSS 10.0, both achieving unauthenticated remote code execution through completely different mechanisms.

CVECVSSProductMechanismAdded to KEVRansomware Use
CVE-2025-3716410.0HPE OneViewUnauthenticated code injection7 Jan 2026Unknown
CVE-2025-1003510.0Fortra GoAnywhere MFTForged license signature enabling deserialization29 Sep 2025Known

Why a perfect 10.0 score means something different depending on which product carries it

CVSS 10.0 requires the maximum possible value on every scoring dimension simultaneously — network-reachable, no privileges required, no user interaction, and complete impact to confidentiality, integrity, and availability, with a changed scope. Both of these vulnerabilities hit that ceiling, but the products they sit in describe two different categories of catastrophic exposure. HPE OneView is infrastructure management software that governs the physical layer underneath everything else — servers, blade enclosures, network fabric. NVD's description of CVE-2025-37164 is notably terse: "A remote code execution issue exists in HPE OneView." That brevity, paired with a public Metasploit exploit module already available in the rapid7/metasploit-framework repository (cited directly in HPE's own advisory references), suggests this is a well-understood, reliably weaponized bug rather than a theoretical scoring exercise — a perfect 10 that attackers can already operationalize with off-the-shelf tooling.

Fortra's GoAnywhere MFT vulnerability tells a more procedurally interesting story. CVE-2025-10035 lives in the License Servlet, and NVD's description specifies the exact precondition: "an actor with a validly forged license response signature" can deserialize an arbitrary actor-controlled object, "possibly leading to command injection." That phrasing — a forged license signature — implies the vulnerability isn't a simple missing-authentication-check bug but a cryptographic validation weakness in how GoAnywhere verifies license responses, which an attacker capable of forging a valid-looking signature can turn into full deserialization-based remote code execution. GoAnywhere MFT's own history as a vulnerable target (the product was also central to a prior wave of Clop ransomware exploitation via a separate 2023 vulnerability) makes CISA's "Known" ransomware-use flag on this CVE unsurprising rather than novel — this is a product family that has demonstrated repeated attractiveness to ransomware operators specifically because MFT platforms sit at the exact junction point between internal networks and external data transfer.

Why management-plane and file-transfer infrastructure deserve the same urgency, for different reasons

HPE OneView's blast radius runs through the hardware it manages — a hypervisor host, network switch, or blade enclosure controller compromised via OneView potentially gives an attacker a foothold beneath the operating system layer that most detection tooling is built to monitor. GoAnywhere MFT's blast radius runs through the data it moves — a managed file transfer platform, by design, already holds the credentials and connectivity needed to reach every system it transfers files between. Neither vulnerability's severity comes from clever chaining; both are direct, single-step paths to unauthenticated RCE, which is precisely why they scored a perfect 10 rather than merely a high critical score.

What to check this week

  • Apply the HPE security bulletin fix for OneView immediately given the public availability of a working Metasploit module — this closes the gap between disclosure and mass exploitability faster than most defenders can react.
  • Confirm GoAnywhere MFT is running a version with the License Servlet fix applied, per Fortra's fi-2025-012 advisory, and treat this as urgent given CISA's confirmed ransomware association.
  • Restrict network reachability to both products' management interfaces to the minimum administrative population required — neither vulnerability requires authentication, so network segmentation is the only mitigation available before patching completes.
  • Review GoAnywhere MFT file transfer logs for the period before patching for any signs of unusual license validation activity or unexpected process execution tied to the License Servlet.

A closing note on infrastructure that operates below the application layer

Both OneView and GoAnywhere MFT are the kind of software that rarely appears in an organization's top-of-mind risk conversations — one manages hardware, the other moves files — compared to customer-facing applications or identity systems. That relative obscurity is exactly why perfect-10 vulnerabilities in products like these can persist unpatched longer than equivalent findings in more visible systems: fewer people are watching for them by default.

A final consideration on GoAnywhere's ransomware history repeating

Fortra's GoAnywhere MFT product family has now produced multiple confirmed ransomware-associated critical vulnerabilities across different years and different underlying flaws. Organizations still running GoAnywhere MFT should treat its historical vulnerability record as an ongoing risk signal about the product category itself, not just about any single patch level.

How Safeguard helps

Safeguard's continuous inventory tracks infrastructure-management and file-transfer platforms with the elevated priority their blast radius warrants, correlating perfect-severity findings like these against actual network exposure so remediation is driven by real reachability rather than by the product's visibility in day-to-day operations.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.