← Vulnerability feed

Vulnerability record · CVE-2018-7123 · published 5 June 2019

CVE-2018-7123: HPE Intelligent Management Center remote denial of service via improper authentication

Hp · Intelligent Management Center

HPE Intelligent Management Center (IMC) PLAT versions earlier than 7.3 E0506P09 contain a remote denial of service flaw tied to improper authentication (CWE-287). A network-reachable attacker can disrupt the platform without credentials or user interaction, which matters because IMC is management infrastructure for network devices.

7.5 CVSS 3.0 High EPSS 58% · top 0.9% CWE-287 · Improper authentication
7.5CVSS 3.0 base score, v2 7.8
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 3.0 rates this 7.5 HIGH for remote unauthenticated availability impact, and EPSS is very high at the 99th percentile, though it is not in KEV and no exploit is referenced.

What it is

HPE Intelligent Management Center (IMC) PLAT versions earlier than 7.3 E0506P09 contain a remote denial of service flaw tied to improper authentication (CWE-287). A network-reachable attacker can disrupt the platform without credentials or user interaction, which matters because IMC is management infrastructure for network devices.

Impact

An attacker can cause a denial of service against the IMC PLAT service, degrading or halting management and monitoring of the managed network. There is no confidentiality or integrity impact per the CVSS vector; only availability is affected.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), per the CVSS 3.0 vector. The description does not specify the exact endpoint or protocol, so the precise entry point is not documented in this record.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, which are vendor advisories only. EPSS is high (0.57691, 99.039th percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Upgrade HPE Intelligent Management Center PLAT to version 7.3 E0506P09 or later as specified in the vendor advisory.
  • Restrict network access to IMC management interfaces to trusted administrative networks and hosts.
  • Place IMC behind firewalls or access control lists so it is not exposed to untrusted networks.
  • Monitor the vendor advisory page for updated guidance and any revised fixed versions.
  • Maintain offline backups and a recovery plan for the IMC platform in case of service disruption.

Detection

  • Monitor IMC PLAT service availability and restart/crash events for unexplained outages.
  • Alert on anomalous or unexpected network traffic to IMC management ports from untrusted sources.
  • Review IMC and host logs for authentication failures or malformed requests preceding service interruptions.
  • Track availability metrics for the IMC platform to catch repeated or sustained denial-of-service conditions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7123 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4822HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remo…EPSS 63%analysed10.0CVE-2012-5201HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified …EPSS 64%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3274HP Intelligent Management Center UAM stack buffer overflow via log dataHP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, tr…EPSS 64%analysed10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2018-7123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.