CVE-2017-12517: Input Validation
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
HPE Intelligent Management Center PLAT version 7.3 (E0504) is identified as affected. The issue is resolved in PLAT 7.3 (E0506) and subsequent versions.
What access does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient and user interaction is not required, but the attacker must already have low-level privileges. Successful exploitation can result in remote code execution with high impacts to confidentiality, integrity, and availability.
What should be done if the affected version is in use?
Upgrade HPE Intelligent Management Center PLAT to version 7.3 (E0506) or a later version. The provided data does not specify a workaround for systems that cannot be upgraded immediately.