PT-2017-3538 · Hewlett Packard · Hpe Intelligent Management Center

Published

2017-01-10

·

Updated

2019-10-03

·

CVE-2017-5822

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04
Description: A Remote Code Execution issue was discovered, related to the dbman service in HPE Intelligent Management Center PLAT. The vulnerability is associated with incorrect handling of Opcode 10010 requests. Exploitation of this issue may allow a remote attacker to write arbitrary files and execute arbitrary code.
Recommendations: For HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04, consider restricting access to the dbman service to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00428
CVE-2017-5822
ZDI-17-337

Affected Products

Hpe Intelligent Management Center