Executive Summary

Summary
Title HP Intelligent Management Center (IMC), Remote Execution of Arbitrary Code
Informations
Name HPSBGN02680 SSRT100361 First vendor Publication 2011-05-05
Vendor HP Last vendor Modification 2011-05-05
Severity (Vendor) N/A Revision 1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Potential security vulnerabilities have been identified with HP Intelligent Management Center (IMC). The vulnerabilities could be exploited to allow remote execution of arbitrary code.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02822750

CWE : Common Weakness Enumeration

% Id Name
57 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
29 % CWE-20 Improper Input Validation
14 % CWE-399 Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3

Open Source Vulnerability Database (OSVDB)

Id Description
72397 HP Intelligent Management Center imcsyslogdm.exe Use-after-free Remote Code E...

HP Intelligent Management Center contains a use-after-free error in the imcsyslogdm.exe component. This may allow a remote attacker to send a crafted syslog packet which is larger than 2048 bytes to UDP port 514 to execute arbitrary code.
72396 HP Intelligent Management Center tftpserver.exe Function Pointer Table TFTP O...

HP Intelligent Management Center contains an indexing error in the tftpserver.exe component when using the TFTP opcode field to access a function pointer table. This may allow a remote attacker to use a large or invalid crafted opcode field to execute arbitrary code.
72395 HP Intelligent Management Center tftpserver.exe TFTP DATA / ERROR Packet Proc...

HP Intelligent Management Center is prone to an overflow condition. The tftpserver.exe component fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted TFTP packet accompanying a 0x03 (DATA) or 0x05 (ERROR) opcode sent to UDP port 69, a remote attacker can potentially execute arbitrary code.
72394 HP Intelligent Management Center tftpserver.exe TFTP Mode Field Processing Ov...

HP Intelligent Management Center is prone to an overflow condition. The tftpserver.exe component fails to properly sanitize user-supplied input when processing TFTP Mode fields, resulting in a stack-based buffer overflow. With a specially crafted long mode field in a packet sent to UDP port 69, a remote attacker can potentially execute arbitrary code.
72393 HP Intelligent Management Center dbman.exe dbman_debug.log Log Message Creati...

HP Intelligent Management Center is prone to an overflow condition. The dbman.exe component suffers from a boundary error when creating log messages which are stored in the 'dbman_debug.log' file, resulting in a stack-based buffer overflow. With a specially crafted packet sent to UDP port 2810, a remote attacker can potentially execute arbitrary code.
72392 HP Intelligent Management Center tftpserver.exe Write Request (WRQ) Packet Pr...

HP Intelligent Management Center contains a flaw related to thetftpserver.exe component allowing the creation or upload of arbitrary files when handling Write Request packets. This may allow a remote attacker to upload arbitrary files which will allow for the execution of arbitrary code as the SYSTEM user.
72391 HP Intelligent Management Center img.exe Packet Field Processing Overflow

HP Intelligent Management Center is prone to an overflow condition. The img.exe component fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted length field in a packet sent to TCP port 8800, a remote attacker can potentially execute arbitrary code.

Snort® IPS/IDS

Date Description
2016-03-14 HP Intelligent Management Center img buffer overflow attempt
RuleID : 36803 - Revision : 2 - Type : SERVER-OTHER
2014-01-10 HP HP Intelligent Management Center syslog remote code execution attempt
RuleID : 25352 - Revision : 7 - Type : SERVER-OTHER
2014-01-10 HP Intelligent Management Center dbman buffer overflow attempt
RuleID : 19649 - Revision : 10 - Type : SERVER-OTHER
2014-01-10 HP Intelligent Management Center TFTP server MODE remote code execution attem...
RuleID : 19014 - Revision : 6 - Type : PROTOCOL-TFTP
2014-01-10 HP Intelligent Management Center TFTP server MODE remote code execution attem...
RuleID : 19013 - Revision : 9 - Type : PROTOCOL-TFTP
2014-01-10 Multiple TFTP product buffer overflow attempt
RuleID : 18767 - Revision : 12 - Type : PROTOCOL-TFTP

Nessus® Vulnerability Scanner

Date Description
2011-06-08 Name : The version of HP Intelligent Management Center running on the remote host is...
File : hp_imc_multiple_code_execution.nasl - Type : ACT_GATHER_INFO
2011-06-07 Name : The version of HP Intelligent Management Center's TFTP server running on the ...
File : tftp_hp_imc_multiple_vulnerabilities.nasl - Type : ACT_ATTACK
2011-05-24 Name : The remote Windows host has an application installed that is affected by mult...
File : hp_intelligent_management_center_code_exec.nasl - Type : ACT_GATHER_INFO