← Vulnerability feed

Vulnerability record · CVE-2012-5201 · published 9 March 2013

CVE-2012-5201: HP Intelligent Management Center remote code execution flaw

Hp · Intelligent Management Center

HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.

10.0 CVSS 2.0 High EPSS 64% · top 0.8%
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1611.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication and full impact, plus a very high EPSS percentile, makes this a top remediation priority despite the thin technical detail.

What it is

HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.

Impact

An unauthenticated remote attacker can execute arbitrary code on the iMC/ANM server, gaining full control of the host and the network management data it holds.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The specific interface or protocol is not described in the record.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is 0.63744 (99.18th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade HP iMC and iMC for ANM to version 5.2 E0401 or later per the HP vendor advisory.
  • Restrict network access to iMC/ANM management interfaces to trusted administrative networks only.
  • Place iMC/ANM behind a firewall or jump host and block direct internet exposure.
  • Monitor HP security bulletins for updated fixes if the E0401 build is not deployable.
  • Audit iMC/ANM service accounts and credentials for signs of compromise after any exposure.

Detection

  • Review iMC/ANM server logs for unexpected process creation or command execution by the application service account.
  • Monitor network traffic to iMC/ANM management ports for anomalous inbound connections from untrusted sources.
  • Check for unexpected files, web shells or new services on iMC/ANM hosts.
  • Correlate IDS/IPS alerts against iMC/ANM endpoints for exploit attempts targeting the management interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5201 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4822HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remo…EPSS 63%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3274HP Intelligent Management Center UAM stack buffer overflow via log dataHP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, tr…EPSS 64%analysed10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%10.0CVE-2011-1853Hp intelligent management center improper input validation vulnerabilitytftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2)…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2012-5201), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.