Improper input validation in HP Intelligent Management Center - CVE-2017-5822

 

Improper input validation in HP Intelligent Management Center - CVE-2017-5822

Published: May 26, 2017


Vulnerability identifier: #VU6783
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5822
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify important information.

The weakness exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted data to TCP port 2810, gain access to user and system data and change it.

Successful exploitation of the vulnerability may result in modification of information.

Affected software

HP Intelligent Management Center

How to mitigate CVE-2017-5822

Update to version 7.3 E0504P04.


External References

Related Security Bulletins