« Back to list

CVE-2019-5390

Status: ModifiedCritical (9.8)—

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-5390",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "HPE Intelligent Management Center (IMC) PLAT",
          "versions": [
            {
              "status": "affected",
              "version": "7.3 E0506P09 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-06-05T15:29:03.793",
  "references": [
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03930en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2019-42",
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03930en_us",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2019-42",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad de inyección remota de comandos en HPE Intelligent Management Center (IMC) PLAT en versiones anteriores a 7.3 E0506P09."
    }
  ],
  "lastModified": "2026-06-17T02:37:36.533",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70962382-6FA5-4E21-81D8-09FE48D77A54",
              "versionEndExcluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AA88901-0BB2-46C5-AAA4-38D41EE656F9"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0503:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8A100F0-6CAE-4705-A2ED-862D0016E3DA"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0504:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5F6C54E-D905-49E3-B848-8401E0B41B5E"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16728216-DDCF-4842-9C7F-02FE7E055E70"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0504p04:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FC4C972-D942-40A3-AFDE-A3A2B34416BB"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0506:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "394C1F2C-5852-4A99-82AD-1B874E8F4164"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0506p03:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB8C4E2F-25CF-4949-A6FE-7FDF6F27B36D"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:7.3:e0506p07:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8344F117-C492-4FF9-A982-B7293E62C5F4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}