HPSBGN02680 SSRT100361 rev.1 - HP Intelligent Management Center (IMC), Remote Execution of Arbitrary Code

  • KM02992700
  • 18-Oct-2017
  • 18-Oct-2017

Summary

Potential security vulnerabilities have been identified with HP Intelligent Management Center (IMC). The vulnerabilities could be exploited to allow remote execution of arbitrary code.

Reference

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: KM02992700 (c02822750)

Version: 1

HPSBGN02680 SSRT100361 rev.1 - HP Intelligent Management Center (IMC), Remote Execution of Arbitrary Code
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2011-05-05

Last Updated: 2011-05-05


Potential Security Impact: Remote execution of arbitrary code

Source: Hewlett Packard Enterprise, HPE Product Security Response Team

VULNERABILITY SUMMARY

Potential security vulnerabilities have been identified with HP Intelligent Management Center (IMC). The vulnerabilities could be exploited to allow remote execution of arbitrary code.

References: 
CVE-2011-1848 (ZDI-CAN-1010)
CVE-2011-1849 (ZDI-CAN-1011)
CVE-2011-1850 (ZDI-CAN-1012)
CVE-2011-1851 (ZDI-CAN-1013)
CVE-2011-1852 (ZDI-CAN-1014)
CVE-2011-1853 (ZDI-CAN-1015)
CVE-2011-1854 (ZDI-CAN-1028)

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP Intelligent Management Center (IMC) PLAT 5.0 (E0101) and IMC PLAT 5.0 (E0101L01) or earlier.

BACKGROUND

CVSS 2.0 Base Metrics

Reference
Base Vector
Base Score
CVE-2011-1848
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1849
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1850
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1851
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1852
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1853
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0
CVE-2011-1854
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
10.0

Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.

The Hewlett-Packard Company thanks Luigi Auriemma, AbdulAziz Hariri of ThirdEyeTesters, and TippingPoint (zdi-disclosures@tippingpoint.com) for reporting these vulnerabilities to security-alert@hp.com

RESOLUTION

HP has made an update available to resolve the vulnerabilities. The update can be downloaded from the following locations:

Product
Version
Location
HP Intelligent Management Center (IMC) Standard Platform
IMC V. 5.0_E0101L02
HP Intelligent Management Center (IMC) Enterprise Platform
IMC V. 5.0_E0101L02

HISTORY 
Version:1 (rev.1) - 5 May 2011 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

©Copyright 2017 Hewlett Packard Enterprise Company, L.P.
Hewlett Packard Enterprise Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HPE nor its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett Packard Enterprise Company and the names of Hewlett Packard Enterprise Company products referenced herein are trademarks of Hewlett Packard Enterprise Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.