CVE-2017-5792
CRITICALHPE Intelligent Management Center PLAT 7.3 E0504P2 - Remote Code Execution via Untrusted Data Deserialization
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-5792. PoCs published by Chris Lyne, scanfsec.
AI-analyzed exploit summary This exploit leverages Java RMI Registry deserialization vulnerability in HPE iMC 7.3 to achieve remote code execution. It uses ysoserial to generate a payload that launches calc.exe on the target system.
Description
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
Exploits (2)
This exploit leverages Java RMI Registry deserialization vulnerability in HPE iMC 7.3 to achieve remote code execution. It uses ysoserial to generate a payload that launches calc.exe on the target system.
This PoC exploits a Java RMI Registry deserialization vulnerability in HPE iMC 7.3 to achieve remote code execution. It uses ysoserial to generate a payload that launches calc.exe on the target system.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H