vendor:
iMC Plat
by:
Chris Lyne
9,8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: iMC Plat
Affected Version From: iMC PLAT v7.2 (E0403) Standard
Affected Version To: iMC PLAT v7.2 (E0403) Standard
Patch Exists: YES
Related CWE: CVE-2017-5816
CPE: a:hewlett_packard:imc_plat:7.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2 Enterprise 64-bit
2017
HP iMC Plat 7.2 dbman Opcode 10008 Command Injection RCE
This exploit allows an attacker to inject arbitrary commands into the HP iMC Plat 7.2 dbman Opcode 10008, which can be used to execute arbitrary code on the vulnerable system. The exploit creates a file 'C:10008.txt' on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the software.