Vulnerability record · CVE-2017-5817 · published 15 February 2018
CVE-2017-5817: HPE Intelligent Management Center input validation flaw enables remote code execution
Hp · Intelligent Management Center
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 contains a remote code execution vulnerability rooted in improper input validation (CWE-20). The record gives no further detail on the vulnerable component or the exact input path, but the flaw is network-reachable and rated critical, so it matters for any organization still running this platform version.
Description
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit code make this an urgent patch-or-isolate case.
What it is
HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 contains a remote code execution vulnerability rooted in improper input validation (CWE-20). The record gives no further detail on the vulnerable component or the exact input path, but the flaw is network-reachable and rated critical, so it matters for any organization still running this platform version.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected iMC server, gaining full control of the host and any data or managed devices it administers.
Attack surface
The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not identify the specific endpoint or protocol involved.
Exploitation
Public exploit code exists, as shown by two Exploit-DB references, and EPSS is very high (0.826, 99.6th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.
What to do
- Upgrade HPE Intelligent Management Center off the affected 7.3 E0504P04 release to a vendor-supported fixed version per HPE advisory hpesbhf03745en_us.
- If patching cannot be done immediately, restrict network access to iMC management interfaces to trusted administrative networks only.
- Place iMC behind a firewall or access-control layer so its management ports are not exposed to untrusted networks or the internet.
- Monitor HPE advisories for updated fixed builds and apply them as they are released.
Detection
- Review iMC server logs and web/proxy logs for unusual requests or command execution patterns against management interfaces.
- Alert on unexpected child processes or command shells spawned by the iMC application or its web server.
- Monitor for outbound connections from the iMC host to unfamiliar external addresses, which may indicate post-exploitation activity.
- Audit network exposure of iMC management ports and flag any that are reachable from untrusted segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1038478 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03745en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/43195/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43492/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038478 | Third Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03745en_us | Vendor Advisory |
| https://www.exploit-db.com/exploits/43195/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43492/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-5817 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5817), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.