CVE-2017-5817
CRITICALHPE Intelligent Management Center < 7.3 - Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2017-5817.
PoCs published by Metasploit, Chris Lyne, sztivi, Chris Lyne, bcoles, including Metasploit module exploits/windows/misc/hp_imc_dbman_restoredbase_unauth_rce.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in HPE iMC's dbman service (OpCode 10007) by injecting commands into the database username field, leading to arbitrary command execution as SYSTEM.
Description
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Exploits (3)
This Metasploit module exploits an unauthenticated command injection vulnerability in HPE iMC's dbman service (OpCode 10007) by injecting commands into the database username field, leading to arbitrary command execution as SYSTEM.
This exploit targets a command injection vulnerability in HP iMC PLAT 7.2 via the dbman service on port 2810. It crafts a malicious packet to execute an arbitrary command (echo to a file) by manipulating opcode 10007.
This Metasploit module exploits an unauthenticated command injection vulnerability in HPE iMC's dbman service (CVE-2017-5817) by sending a crafted RestoreDBase packet with an unsanitized database username field, allowing arbitrary command execution as SYSTEM.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H