vendor:
Intelligent Management Center (iMC) PLAT
by:
Chris Lyne
9,8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: Intelligent Management Center (iMC) PLAT
Affected Version From: iMC PLAT v7.2 (E0403) Standard
Affected Version To: iMC PLAT v7.2 (E0403) Standard
Patch Exists: YES
Related CWE: CVE-2017-5817
CPE: a:hpe:intelligent_management_center_plat
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2 Enterprise 64-bit
2017
HP iMC Plat 7.2 dbman Opcode 10007 Command Injection RCE
A vulnerability in HPE Intelligent Management Center (iMC) PLAT prior to version 7.3 E0504 allows an authenticated remote attacker to execute arbitrary commands with root privileges. The vulnerability exists due to insufficient validation of user-supplied input in the dbman Opcode 10007. An attacker can exploit this vulnerability by sending a specially crafted packet to the dbman service on port 2810/TCP. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands with root privileges.
Mitigation:
Upgrade to HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504 or later.