Vulnerability record · CVE-2017-5816 · published 15 February 2018
CVE-2017-5816: HPE Intelligent Management Center improper input validation remote code execution
Hp · Intelligent Management Center
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 contains an improper input validation flaw (CWE-20) that allows remote code execution. The vulnerability is network-reachable with no authentication or user interaction required, and public exploit code exists. It matters because iMC is a management platform, so compromise can expose broad network control.
Description
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, public exploit code, and very high EPSS make this an urgent remote code execution risk.
What it is
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 contains an improper input validation flaw (CWE-20) that allows remote code execution. The vulnerability is network-reachable with no authentication or user interaction required, and public exploit code exists. It matters because iMC is a management platform, so compromise can expose broad network control.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected iMC server, gaining full control of the host and potentially the managed network infrastructure.
Attack surface
Reached over the network via the iMC PLAT service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.
Exploitation
Public exploit code is referenced on Exploit-DB, and EPSS is 0.86202 (99.7th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply the HPE vendor advisory fix for iMC PLAT 7.3 E0504P04 or upgrade to a supported patched release.
- Restrict network access to iMC management interfaces to trusted administrative networks only.
- Place iMC behind a firewall or VPN and avoid exposing it directly to the internet.
- Monitor for and block known exploit traffic against iMC endpoints.
- If patching is delayed, isolate the iMC server and limit its reach to managed devices.
Detection
- Monitor iMC server logs and network traffic for unusual requests or command execution patterns.
- Alert on unexpected child processes or outbound connections originating from the iMC host.
- Use IDS/IPS signatures for known iMC exploit attempts and review Exploit-DB PoC behavior for matching indicators.
- Audit iMC access logs for unauthenticated or anomalous requests to management endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/100470 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038478 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03745en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/43198/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43493/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/100470 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038478 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03745en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/43198/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43493/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-5816 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5816), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.