Vulnerability record · CVE-2020-7200 · published 18 December 2020
CVE-2020-7200: HPE Systems Insight Manager AMF deserialization remote code execution
Hp · Systems Insight Manager
HPE Systems Insight Manager (SIM) version 7.6 contains a deserialization flaw reachable through AMF handling that permits remote code execution. The record gives no root-cause detail beyond the AMF deserialization reference title, but the impact is severe because SIM is a management platform. A public exploit write-up exists, so unpatched instances are at real risk.
Description
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code available, and very high EPSS probability make this an urgent patch target.
What it is
HPE Systems Insight Manager (SIM) version 7.6 contains a deserialization flaw reachable through AMF handling that permits remote code execution. The record gives no root-cause detail beyond the AMF deserialization reference title, but the impact is severe because SIM is a management platform. A public exploit write-up exists, so unpatched instances are at real risk.
Impact
An unauthenticated remote attacker can execute arbitrary code on the SIM server, gaining full control of the host and potentially the systems it manages.
Attack surface
Reached over the network via the AMF endpoint, per the CVSS vector AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. The exact exposed port or service is not stated in the record.
Exploitation
Not listed in CISA KEV, but EPSS is 0.8189 (99.6th percentile) and a Packet Storm exploit reference is tagged Exploit, indicating public exploit code is available.
What to do
- Apply the HPE vendor advisory fix for SIM 7.6 (emr_na-hpesbgn04068en_us) or upgrade to a supported release.
- Restrict network access to the SIM AMF service to trusted management hosts only.
- If patching is delayed, isolate or take offline internet-facing SIM instances.
- Monitor HPE advisories for updated guidance and confirm the installed SIM version against the fixed release.
Detection
- Monitor SIM server logs and network traffic for unexpected AMF requests from untrusted sources.
- Alert on child processes spawned by the SIM service, especially shells or scripting interpreters.
- Watch for outbound connections or file writes from the SIM host that deviate from baseline behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/161721/HPE-Systems-Insight-Manager-AMF-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04068en_us | Vendor Advisory |
| http://packetstormsecurity.com/files/161721/HPE-Systems-Insight-Manager-AMF-Deserialization-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04068en_us | Vendor Advisory |
Track CVE-2020-7200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.