Vulnerability record · CVE-2019-11945 · published 5 June 2019
CVE-2019-11945: HPE Intelligent Management Center deserialization flaw enables remote code execution
Hp · Intelligent Management Center
HPE Intelligent Management Center (IMC) PLAT before version 7.3 E0506P09 contains a deserialization of untrusted data vulnerability (CWE-502) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction required, making it a serious risk for exposed IMC deployments.
Description
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and very high EPSS make this an urgent patching priority despite no KEV listing.
What it is
HPE Intelligent Management Center (IMC) PLAT before version 7.3 E0506P09 contains a deserialization of untrusted data vulnerability (CWE-502) that allows remote code execution. The flaw is network-reachable with no authentication or user interaction required, making it a serious risk for exposed IMC deployments.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected IMC server, potentially gaining full control of the host and any managed network infrastructure.
Attack surface
The vulnerability is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any exposed IMC service is directly attackable. No authentication is needed to trigger the deserialization path.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit references beyond vendor advisories, but EPSS is very high (0.78644, 99.566th percentile), indicating a strong likelihood of exploitation activity.
What to do
- Upgrade HPE Intelligent Management Center PLAT to version 7.3 E0506P09 or later as the primary fix.
- Restrict network access to IMC management interfaces to trusted administrative networks only.
- Place IMC behind a firewall or VPN and avoid exposing it directly to the internet.
- Monitor vendor advisories for additional patches or workarounds if immediate upgrade is not possible.
- Apply the principle of least privilege to the IMC service account to limit post-exploitation impact.
Detection
- Monitor for unexpected child processes or command execution spawned by the IMC service.
- Inspect network traffic to IMC management ports for anomalous serialized payloads or unusual request patterns.
- Review IMC and host logs for deserialization errors, crashes, or unauthorized access attempts.
- Use endpoint detection to flag suspicious process creation or file writes originating from the IMC server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-11945 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11945), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.