Lucene search

K
cveHpeCVE-2020-7147
HistoryOct 19, 2020 - 6:15 p.m.

CVE-2020-7147

2020-10-1918:15:15
CWE-917
hpe
web.nvd.nist.gov
29
cve-2020-7147
hpe intelligent management center
imc
deployselectbootrom
injection vulnerability
remote code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.006

Percentile

79.0%

A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

Affected configurations

Nvd
Node
hpintelligent_management_centerRange<7.3
OR
hpintelligent_management_centerMatch7.3-
OR
hpintelligent_management_centerMatch7.3e0501
OR
hpintelligent_management_centerMatch7.3e0503
OR
hpintelligent_management_centerMatch7.3e0503p02
OR
hpintelligent_management_centerMatch7.3e0504
OR
hpintelligent_management_centerMatch7.3e0504p02
OR
hpintelligent_management_centerMatch7.3e0504p04
OR
hpintelligent_management_centerMatch7.3e0504p2
OR
hpintelligent_management_centerMatch7.3e0504p4
OR
hpintelligent_management_centerMatch7.3e0506
OR
hpintelligent_management_centerMatch7.3e0506p02
OR
hpintelligent_management_centerMatch7.3e0506p03
OR
hpintelligent_management_centerMatch7.3e0506p07
OR
hpintelligent_management_centerMatch7.3e0506p09
OR
hpintelligent_management_centerMatch7.3e0605
OR
hpintelligent_management_centerMatch7.3e0605h02
OR
hpintelligent_management_centerMatch7.3e0605h05
OR
hpintelligent_management_centerMatch7.3e0605p04
OR
hpintelligent_management_centerMatch7.3e0605p06
OR
hpintelligent_management_centerMatch7.3e0705
OR
hpintelligent_management_centerMatch7.3e0705p02
OR
hpintelligent_management_centerMatch7.3e0705p04
OR
hpintelligent_management_centerMatch7.3e0705p06
VendorProductVersionCPE
hpintelligent_management_center*cpe:2.3:a:hp:intelligent_management_center:*:*:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:-:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0501:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0503:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0503p02:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0504:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p02:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p04:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p2:*:*:*:*:*:*
hpintelligent_management_center7.3cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p4:*:*:*:*:*:*
Rows per page:
1-10 of 241

CNA Affected

[
  {
    "product": "HPE Intelligent Management Center (iMC)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Prior to iMC PLAT 7.3 (E0705P07)"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.006

Percentile

79.0%

Related for CVE-2020-7147