← Vulnerability feed

Vulnerability record · CVE-2018-7092 · published 6 August 2018

CVE-2018-7092: HPE Intelligent Management Center path traversal allows arbitrary file deletion

Hp · Intelligent Management Center

HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09 contains a path traversal flaw (CWE-22) that can be reached remotely. An attacker can traverse directories to delete arbitrary files, which threatens availability and integrity of the management platform. The record names only this single version and gives no further detail on the vulnerable component.

7.5 CVSS 3.0 High EPSS 53% · top 1.1% CWE-22 · Path traversal
7.5CVSS 3.0 base score, v2 6.4
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09. The vulnerability could be remotely exploited to allow for remote directory traversal leading to arbitrary file deletion.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file deletion with a high EPSS score, though no KEV listing or known exploit is documented.

What it is

HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09 contains a path traversal flaw (CWE-22) that can be reached remotely. An attacker can traverse directories to delete arbitrary files, which threatens availability and integrity of the management platform. The record names only this single version and gives no further detail on the vulnerable component.

Impact

An unauthenticated remote attacker can delete arbitrary files on the host, potentially disrupting IMC services or destroying configuration and data. The CVSS vector scores integrity impact only (I:H), with no confidentiality or availability component recorded.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is network-reachable with no authentication and no user interaction. The description does not identify the specific endpoint or parameter used for traversal.

Exploitation

CVE-2018-7092 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at 0.527 (99th percentile), indicating elevated likelihood of exploitation activity. References are vendor and third-party advisories only, with no public exploit tag.

What to do

  • Apply the HPE vendor fix for IMC Plat 7.3 E0506P09 per HPE security bulletin hpesbhf03872en_us, or upgrade to a supported release.
  • Restrict network access to IMC management interfaces to trusted administrative networks and block exposure to the internet.
  • Run IMC services with least privilege and isolate the host so file deletion cannot reach critical system or backup paths.
  • Maintain offline backups of IMC configuration and data to recover from destructive file deletion.
  • Monitor vendor advisories for updated guidance since the record names only one affected version.

Detection

  • Alert on file deletion or modification events in IMC installation and data directories outside normal maintenance windows.
  • Monitor IMC web logs for traversal sequences such as ../ or encoded variants in request paths and parameters.
  • Baseline and integrity-check critical IMC files and configuration to detect unexpected removal.
  • Watch for anomalous unauthenticated requests to IMC management endpoints from external or unusual source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7092 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4822HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remo…EPSS 63%analysed10.0CVE-2012-5201HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified …EPSS 64%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3274HP Intelligent Management Center UAM stack buffer overflow via log dataHP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, tr…EPSS 64%analysed10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2018-7092), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.