CVE-2020-24652

Description

A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.729

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0506p07NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0506p03NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0506p02NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0504p4NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0504p04NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.0-e02020p03NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.0NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0705p06NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0705p04NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0705p02NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0705NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0605p06NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0504p2NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0504NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0503NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403p06NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0503p02NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0-e0101l02NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0-e0101l01NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0-e0101h04NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0-e0101h03NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0-e0101NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.0NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0506p09NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0605p04NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0605h05NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0605h02NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0605NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0506NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0504p02NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.1-e0202-enterpriseNCM
Multiple Vulnerabilities affected in intelligent_management_center 5.1-e0202NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.1-e0101p01NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.1NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.3-e0501NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403p10NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403p04NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403p03NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403l09NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403l02NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403l01NCM
Multiple Vulnerabilities affected in intelligent_management_center 7.2-e0403NCM
Multiple Vulnerabilities affected in intelligent_management_center 5.2NCM
Improper Neutralization of Special Elements used in an Expression Language Statement (Expression Language Injection) Vulnerability (CVE-2020-24652)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234