Impact
An authentication bypass flaw in HPE Intelligent Management Center allows attackers to gain access without valid credentials. The vulnerability exploits an improper authorization check, enabling the attacker to obtain the same privileges as a legitimate user and potentially alter system configuration or data. This weakness can compromise the confidentiality, integrity, and availability of managed resources.
Affected Systems
Hewlett Packard Enterprise’s HPE Intelligent Management Center is affected in all releases prior to version 7.3 E0713. Any deployment using those versions is vulnerable and requires remediation.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical issue. Although no EPSS data is available and the vulnerability is not listed in CISA KEV, the risk of exploitation remains significant. The likely attack vector is remote across the management interface, where an attacker can craft a request to bypass the authentication mechanism and gain full system control. The ease of exploitation and the high impact warrant urgent attention.
OpenCVE Enrichment