Vulnerability record · CVE-2019-5355 · published 5 June 2019
CVE-2019-5355: HPE Intelligent Management Center remote denial of service via expression language injection
Hp · Intelligent Management Center
HPE Intelligent Management Center (IMC) PLAT before version 7.3 E0506P09 contains a remote denial of service flaw tied to expression language injection (CWE-917). An unauthenticated network attacker can disrupt the platform, which matters because IMC is management infrastructure that many other network devices depend on.
Description
A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote availability impact on management infrastructure with a high EPSS score, though no confirmed in-the-wild exploitation is documented.
What it is
HPE Intelligent Management Center (IMC) PLAT before version 7.3 E0506P09 contains a remote denial of service flaw tied to expression language injection (CWE-917). An unauthenticated network attacker can disrupt the platform, which matters because IMC is management infrastructure that many other network devices depend on.
Impact
An attacker can cause a denial of service against the IMC platform, degrading or halting management and monitoring of the managed network. The CVSS vector shows availability impact only, with no confidentiality or integrity loss.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which interface or endpoint is targeted.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tag appears in the references, which are vendor advisories only. EPSS is high at roughly 0.54 (99th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade HPE Intelligent Management Center PLAT to version 7.3 E0506P09 or later, per the vendor advisory.
- Restrict network access to IMC management interfaces to trusted administrative networks and block exposure to the internet.
- Monitor the vendor advisory page for updated guidance and any revised fixed builds.
- Segment IMC from general user networks so a DoS against it does not cascade to managed devices.
Detection
- Alert on IMC service crashes, restarts or unavailability events and correlate them with inbound network connections.
- Baseline and monitor request rates and payload patterns to IMC web endpoints for expression-language style input.
- Review IMC and host logs for repeated failed or anomalous requests from single sources preceding outages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-5355 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5355), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.