Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service

Ryan Seguin

Tenable Research discovered multiple vulnerabilities in the HPE Intelligent Management Center. HPE is currently working to fix the issues and plans to release patches on Nov. 30.

  • What you need to know: Multiple vulnerabilities were found in HPE iMC, ranging from denial-of-service (DoS) to remote code execution.
  • What’s the attack vector? Multiple listening ports related to HPE iMC.
  • What’s the business impact? Potential DoS, information disclosure, and asset takeover.
  • What’s the solution? There are no patches or workarounds currently. HPE plans to release a patch on or around Nov. 30.

Background

Tenable researcher Chris Lyne discovered several security vulnerabilities in the HPE Intelligent Management Center (HPE iMC). HPE iMC is a network management tool used to monitor assets and their configurations. HPE iMC is often deployed as a large-scale enterprise virtual/physical management solution.

These vulnerabilities include two DoS attacks, two information disclosures, and a remote code execution (RCE). The dbman service could also allow a remote, unauthenticated user to trigger a manual backup to an arbitrary location on the file system.

Analysis

Two vulnerabilities were discovered in HPE iMC’s “dbman.exe” process that can potentially lead to DoS attacks. By sending malicious messages to port 2810, an attacker could cause a stack based buffer overflow, or reboot the service gracefully.

The remote code execution vulnerability was discovered in HPE iMC's JMX service, which listens on TCP port 9091 by default. This vulnerability can be exploited remotely without authentication. The vulnerability exists due to JMX being configured to start without requiring authentication.

Identifying affected assets

Tenable has released plugins to scan for these issues.

Vendor response

Tenable Research has contacted HP about these vulnerabilities. HP has confirmed it’s aware, and a fix for this will be available in an upcoming release. At the time of publication, HP projects a fix for this issue will be available on or around Nov. 30.

Additional information

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

Read more >

Published on Oct 11, 2018

People also viewed

Customer Success Manager - ANZ

North Sydney Australia Pacific Highway, North Sydney, Australia, NSW 2060 Customer Success Sales
Your Role:Tenable has an immediate need for a Customer Success Manager who will be responsible for establishing and driving sales activities for our software products within a designated geography.Companies today are grappling with an ever expandi...

Field and Channel Marketing Manager, Nordics and Benelux

Uxbridge United Kingdom Furzeground Way , Stockley Park, Uxbridge, United Kingdom, UB11 1EZ Field & Channel Marketing Marketing
Your Role:Tenable seeks an experienced field and channel marketing manager to generate demand for Tenable products and solutions across our Scandinavia and Benelux territories.  The successful candidate will have demonstrated experience creating, ...

Finance & Investor Relations Intern

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 21046 Finance Internships
Your Role:Tenable has a Finance and Investor Relations Intern opportunity for college students entering their senior year or actively enrolled in an MBA program. If you're looking for a chance to apply what you're learning in your degree program, ...

Senior Data Engineer

Dublin Ireland Campshires, Sir John Rogerson's Quay, Dublin, Ireland Research Engineering
Your Role:Data Engineers here are involved in designing, developing and maintaining systems for data analysis, transformation, modelling and visualisation. We work directly with the data scientists to develop cutting edge uses of the data we colle...

Technical Support Manager

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 21046 Technical Support Technical Support
Your Role:Tenable is seeking a high energy, results oriented customer advocate capable of motivating an already exceptional support team to even higher levels of customer satisfaction. Our current global rating is over 93% satisfaction and we expe...

Cloud Security Intern

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 21046 Information Security Internships
Your Role: The Cloud Security Intern will help the Tenable secure their use of cloud systems across the company.  The intern will develop, implement and monitor security solutions for cloud that assess risk, keep Tenable data safe and bake in secu...

We have big plans for continued global growth, and we’re looking for people who are creative, flexible and dedicated to helping us build something great – something that matters.