vendor:
iMC PLAT
by:
Chris Lyne
9.8
CVSS
CRITICAL
Java RMI Registry Deserialization RCE
502
CWE
Product Name: iMC PLAT
Affected Version From: HPE iMC PLAT v7.3 (E0504) Standard
Affected Version To: HPE iMC PLAT v7.3 (E0504) Standard
Patch Exists: YES
Related CWE: CVE-2017-5792
CPE: a:hewlett_packard:imc_plat:7.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2008 R2 Enterprise 64-bit
2018
HPE iMC 7.3 Java RMI Registry Deserialization RCE Vulnerability
Chris Lyne (@lynerc) discovered a vulnerability in HPE iMC PLAT v7.3 (E0504) Standard, which allows remote attackers to execute arbitrary code via a crafted serialized Java object to the RMI service. This PoC will launch calc.exe.
Mitigation:
Update to the latest version of HPE iMC PLAT v7.3 (E0504) Standard.