← Vulnerability feed

Vulnerability record · CVE-2016-8530 · published 15 February 2018

CVE-2016-8530: HPE iMC PLAT improper input validation remote denial of service

Hp · Intelligent Management Center

HPE iMC PLAT v7.2 E0403P06 and earlier contain an improper input validation flaw (CWE-20) that allows a remote, unauthenticated attacker to cause a denial of service. The issue was fixed in iMC PLAT 7.3 E0504 and later, so unpatched deployments remain exposed.

7.5 CVSS 3.0 High EPSS 48% · top 1.2% CWE-20 · Improper input validation
7.5CVSS 3.0 base score, v2 5.0
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 3.0 base score is 7.5 (HIGH) with network reachability, no authentication and no user interaction, and EPSS is near the top percentile, though no KEV listing or confirmed public exploit is present.

What it is

HPE iMC PLAT v7.2 E0403P06 and earlier contain an improper input validation flaw (CWE-20) that allows a remote, unauthenticated attacker to cause a denial of service. The issue was fixed in iMC PLAT 7.3 E0504 and later, so unpatched deployments remain exposed.

Impact

An attacker can disrupt availability of the iMC PLAT management platform, potentially taking management and monitoring functions offline. There is no confidentiality or integrity impact per the CVSS vector; the effect is availability loss.

Attack surface

The flaw is reachable over the network with no authentication and no user interaction required (CVSS:3.0/AV:N/AC:L/PR:N/UI:N). The record does not specify which interface or endpoint is affected.

Exploitation

Not listed in CISA KEV and no public exploit is confirmed by the reference tags, which are only Vendor Advisory and Third Party Advisory. EPSS is high (0.48035, ~98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade to iMC PLAT 7.3 E0504 or a later version as directed by the HPE advisory.
  • If immediate upgrade is not possible, restrict network access to the iMC PLAT management interface to trusted management networks only.
  • Monitor the HPE advisory page for any updated guidance or interim fixes.
  • Review iMC PLAT exposure to untrusted networks and remove any direct internet-facing access.

Detection

  • Monitor iMC PLAT service availability and restart events for unexplained outages or crashes.
  • Alert on abnormal or malformed request patterns reaching iMC PLAT management endpoints.
  • Correlate iMC PLAT process crash or hang logs with inbound network activity from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8530 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4822HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remo…EPSS 63%analysed10.0CVE-2012-5201HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified …EPSS 64%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3274HP Intelligent Management Center UAM stack buffer overflow via log dataHP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, tr…EPSS 64%analysed10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2016-8530), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.