CVE-2017-12505: Input Validation
Published Feb 15, 2018
·Updated
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Affected Software
1 affected component
HP Intelligent Management Center=7.3-e0504
Event History
Feb 15, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is possible over the network with low attack complexity, but requires low-level privileges. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can result in remote code execution and has high confidentiality, integrity, and availability impact according to the CVSS vector.
3
Which versions are known to be affected and fixed?
HPE Intelligent Management Center PLAT 7.3 (E0504) is identified as affected. The issue is resolved in PLAT 7.3 (E0506) and subsequent versions.