CVE-2017-12525: Input Validation
Published Feb 15, 2018
·Updated
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Affected Software
1 affected component
HP Intelligent Management Center=7.3-e0504
Event History
Feb 15, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected and which versions contain the fix?
The affected release identified is HPE Intelligent Management Center PLAT 7.3 (E0504). HPE states that PLAT 7.3 (E0506) and subsequent versions resolve the issue.
2
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient to reach the vulnerable service, but the attacker must have low-level privileges. No user interaction is required.
3
What impact could successful exploitation have?
Successful exploitation can result in remote code execution. The CVSS vector rates confidentiality, integrity, and availability impact as high.