Vulnerability record · CVE-2017-12557 · published 15 February 2018
CVE-2017-12557: HPE iMC PLAT deserialization flaw allows remote code execution
Hp · Intelligent Management Center
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 and earlier contains a deserialization of untrusted data flaw (CWE-502) that permits remote code execution. The vulnerability is network-reachable with no authentication or user interaction, and a public exploit exists, making it a serious risk for exposed iMC deployments.
Description
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and a public exploit make this a critical remote code execution risk.
What it is
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 and earlier contains a deserialization of untrusted data flaw (CWE-502) that permits remote code execution. The vulnerability is network-reachable with no authentication or user interaction, and a public exploit exists, making it a serious risk for exposed iMC deployments.
Impact
An unauthenticated remote attacker can execute arbitrary code on the iMC server, gaining full control of the host and potentially the managed network infrastructure it administers.
Attack surface
Reachable over the network via the iMC PLAT service; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required. The description does not specify the exact endpoint or protocol.
Exploitation
A public exploit is referenced on Exploit-DB, and EPSS is very high (0.798, 99.6th percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild activity is documented in this record.
What to do
- Apply the HPE vendor advisory fix for iMC PLAT 7.3 E0504P2 and earlier; upgrade to a patched release.
- Restrict network access to iMC management interfaces to trusted administrative networks only.
- Place iMC behind a firewall or VPN and avoid exposing it directly to the internet.
- Monitor for and block deserialization attack patterns against iMC services.
- Review iMC logs for unexpected process execution or anomalous requests.
Detection
- Monitor iMC server logs for unusual deserialization or serialized object payloads in HTTP requests.
- Alert on unexpected child processes spawned by the iMC Java service.
- Track outbound connections from the iMC host to unfamiliar external addresses.
- Use the Exploit-DB PoC to build signatures for known exploit traffic against iMC endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101152 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039495 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03778en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/45952/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101152 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039495 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03778en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/45952/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-12557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.