VulnerabilityModified
CVE-2017-5791
The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.
CRITICAL 9.8EPSS 68.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 68.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 68.92% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- hp/intelligent management center plat
- Source
- security-alert@hpe.com
References
- http://www.securityfocus.com/bid/101224Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/96815Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037983Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-161/Third Party Advisory, VDB Entry
- https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03716en_usVendor Advisory
- http://www.securityfocus.com/bid/101224Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/96815Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037983Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-17-161/Third Party Advisory, VDB Entry
- https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03716en_usVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.