7.5
CVSSv3

CVE-2017-8982

Published: 15/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hp intelligent management center 7.3

Exploits

# Exploit Title: HPE iMC EL Injection Unauthenticated RCE # Date: 6 February, 2018 # Exploit Author: TrendyTofu # Vendor Homepage: wwwhpecom/us/en/homehtml # Software Link: h10145www1hpecom/Downloads/SoftwareReleasesaspx?ProductNumber=JG747AAE&lang=en&cc=us&prodSeriesId=4176535 # Version: prior to 73 E0504P04 # Te ...
This Metasploit module exploits an expression language injection vulnerability, along with an authentication bypass vulnerability in Hewlett Packard Enterprise Intelligent Management Center before version 73 E0504P04 to achieve remote code execution The HP iMC server suffers from multiple vulnerabilities allows unauthenticated attacker to execute ...