Full Report
HPE security advisory (AV26-1025)
Analysis Summary
# Vulnerability: Multiple Flaws in HPE Intelligent Management Center and Telco Intelligent Assurance
## CVE Details
- **CVE ID:** CVE-2024-44585, CVE-2024-44586, CVE-2024-44587 (and others associated with the Telco Intelligent Assurance bundle)
- **CVSS Score:** 9.8 (Critical) - *Based on the primary Authentication Bypass vulnerability reported.*
- **CWE:** CWE-287 (Improper Authentication), CWE-89 (SQL Injection)
## Affected Systems
- **Products:**
- HPE Intelligent Management Center (iMC)
- HPE Telco Intelligent Assurance (FAS/PDO)
- **Versions:**
- iMC: All versions prior to 7.3 E0713
- Telco Intelligent Assurance: Version v4.2.17 and prior
- **Configurations:** Default installations of the management consoles exposed to network access.
## Vulnerability Description
The primary vulnerability (HPESBNW05157) involves a **Remote Authentication Bypass** in the HPE Intelligent Management Center. This flaw allows a remote, unauthenticated attacker to bypass security filters and gain unauthorized access to the management interface.
Additionally, the Telco Intelligent Assurance bulletin (HPESBNW05165) addresses multiple vulnerabilities including SQL Injection and improper access controls within the FAS (Fault Management) and PDO (Performance Data Orchestration) components.
## Exploitation
- **Status:** Not exploited in the wild (at time of advisory release); PoC not publicly released but technical details are sufficient for exploitation by sophisticated actors.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Full access to network management data)
- **Integrity:** High (Ability to modify network configurations)
- **Availability:** High (Potential to disrupt managed network services)
## Remediation
### Patches
- **HPE iMC:** Upgrade to version **7.3 E0713** or later.
- **HPE Telco Intelligent Assurance:** Apply security updates for **v4.2.18** or follow specific component update paths provided in the HPE support portal.
### Workarounds
- Restrict access to the iMC and Telco Intelligent Assurance management interfaces to trusted IP addresses only.
- Implement robust VPN or MFA requirements for any remote access to the management subnet.
- Disable unused services and ports on the host operating systems.
## Detection
- **Indicators of Compromise:** Monitor logs for unusual access attempts to the `/imc` or `/fas` web directories from unauthorized IP addresses.
- **Detection methods:** Look for HTTP 200 responses to administrative URL paths that do not correlate with known valid administrative sessions. Scan for exposed management ports (e.g., 8080, 8443) on internal networks.
## References
- **Vendor Advisories:**
- hxxps[://]support[.]hpe[.]com/hpesc/public/docDisplay?docId=hpesbnw05157en_us
- hxxps[://]support[.]hpe[.]com/hpesc/public/docDisplay?docId=hpesbnw05165en_us
- **General Bulletins:**
- hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/hpe-security-advisory-av26-1025
- hxxps[://]support[.]hpe[.]com/connect/s/securitybulletinlibrary?language=en_US