← Vulnerability feed

Vulnerability record · CVE-2020-7200 · published 18 December 2020

CVE-2020-7200: HPE Systems Insight Manager AMF deserialization remote code execution

Hp · Systems Insight Manager

HPE Systems Insight Manager (SIM) version 7.6 contains a deserialization flaw reachable through AMF handling that permits remote code execution. The record gives no root-cause detail beyond the AMF deserialization reference title, but the impact is severe because SIM is a management platform. A public exploit write-up exists, so unpatched instances are at real risk.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.4%
9.8CVSS 3.1 base score, v2 7.5
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code available, and very high EPSS probability make this an urgent patch target.

What it is

HPE Systems Insight Manager (SIM) version 7.6 contains a deserialization flaw reachable through AMF handling that permits remote code execution. The record gives no root-cause detail beyond the AMF deserialization reference title, but the impact is severe because SIM is a management platform. A public exploit write-up exists, so unpatched instances are at real risk.

Impact

An unauthenticated remote attacker can execute arbitrary code on the SIM server, gaining full control of the host and potentially the systems it manages.

Attack surface

Reached over the network via the AMF endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The exact exposed port or service is not stated in the record.

Exploitation

Not listed in CISA KEV, but EPSS is 0.8189 (99.6th percentile) and a Packet Storm exploit reference is tagged Exploit, indicating public exploit code is available.

What to do

  • Apply the HPE vendor advisory fix for SIM 7.6 (emr_na-hpesbgn04068en_us) or upgrade to a supported release.
  • Restrict network access to the SIM AMF service to trusted management hosts only.
  • If patching is delayed, isolate or take offline internet-facing SIM instances.
  • Monitor HPE advisories for updated guidance and confirm the installed SIM version against the fixed release.

Detection

  • Monitor SIM server logs and network traffic for unexpected AMF requests from untrusted sources.
  • Alert on child processes spawned by the SIM service, especially shells or scripting interpreters.
  • Watch for outbound connections or file writes from the SIM host that deviate from baseline behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed8.8CVE-2015-8651Adobe Flash Player Integer Overflow Allows Remote Code ExecutionAdobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via uns…KEVEPSS 68%analysed10.0CVE-2007-2719Hp systems insight manager improper authentication vulnerabilitySession fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting …EPSS 4.5%9.8CVE-2016-4366Hp systems insight manager vulnerabilityHPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via…EPSS 4.4%9.1CVE-2016-2029Hp systems insight manager vulnerabilityHPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a diffe…EPSS 4.2%9.1CVE-2016-2018Hp systems insight manager vulnerabilityHPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors.EPSS 3.8%8.5CVE-2012-1999Hp systems insight manager vulnerabilityUnspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote authenticated users to obtain sensitive information or modify …EPSS 2.4%8.1CVE-2016-4358Hp matrix operating environment vulnerabilityHPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a diffe…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-7200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.