HPE Fixes Critical Zero-Day in Server Management Software
#1
Information 
Quote:Hewlett Packard Enterprise (HPE) has fixed a critical zero-day remote code execution (RCE) flaw in its HPE Systems Insight Manager (SIM) software for Windows that it originally disclosed in December.
 
HPE SIM is a tool that enables remote support automation and management for a variety of HPE servers, including the HPE ProLiant Gen10 and HPE ProLiant Gen9, as well as for storage and networking products.
 
The company updated its initial security advisory on Thursday. More than a month ago, on April 20, HPE had issued an earlier SIM hotfix update kit that resolves the vulnerability.
 
This is an extremely high-risk flaw that can enable attackers with no privileges to remotely execute code: Tracked as CVE-2020-7200, it’s rated 9.8 out of a maximum 10. It’s found in the latest versions (7.6.x) of HPE’s SIM software and only affects the Windows version.
 
This bug allows low-complexity attacks that don’t require user interaction. As Packet Storm has explained, it allows attackers to execute code within the context of HPE SIM’s hpsimsvc.exe process, which runs with administrative privileges.
 
The problem stems from a failure to validate data during the deserialization process when a user submits a POST request to the /simsearch/messagebroker/amfsecure page. “This module exploits this vulnerability by leveraging an outdated copy of Commons Collection, namely 3.2.2, that ships with HPE SIM, to gain remote code execution as the administrative user running HPE SIM,” according to Packet Storm. The lack of proper validation of user-supplied data can lead to the deserialization of untrusted data, enabling attackers to execute code on servers running vulnerable SIM software.

Read more: HPE Fixes Critical Zero-Day in SIM | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdwCleaner 8.8.1
AdwCleaner 8.8.1 ...harlan4096 — 08:14
Brave 1.90.122 (Chromium 148.0.7778.167)
Release v1.90.122 ...harlan4096 — 08:12
Privazer 4.0.122 (13 May 2026)
Privazer v4.0.122 ...harlan4096 — 08:11
Google Announces Major Android Auto Upda...
Google has announc...harlan4096 — 08:10
QOwnNotes
26.5.10 Added a f...Kool — 06:46

[-]
Birthdays
Today's Birthdays
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>