重要脆弱性情報 ドキュメントID: HPESBHF03764 rev.3 タイトル: HPE Intelligent Management Center (iMC) PLAT、リモートコード実行 公開日: 2017-06-29 最終更新日: 2017-06-30 潜在的なセキュリティ影響: リモート: コード実行 情報元: Hewlett Packard Enterprise、HPE Product Security Response Team 脆弱性概要 脆弱性説明: HPE Intelligent Management Center (iMC) PLATにおいて、潜在的なセキュリティ脆弱性が発見されました。これらの脆弱性はリモートから悪用され、リモートコード実行を可能にする可能性があります。 関連CVE: - CVE-2017-8954 - ZDI-CAN-4426 - CVE-2017-8955 - ZDI-CAN-4425 - CVE-2017-8957 - ZDI-CAN-4380 サポート対象ソフトウェアバージョン 影響を受けるバージョンのみ: HPE Intelligent Management Center (iMC) PLAT 7.2 CVSSスコア CVE-2017-8954: V3 Base Score: 10.0、V2 Base Score: 10.0 CVE-2017-8955: V3 Base Score: 8.6、V2 Base Score: 7.8 CVE-2017-8957: V3 Base Score: 9.8、V2 Base Score: 10.0 解決策 HPEは、Intelligent Management Center (iMC) PLAT 7.2バージョンの脆弱性を解決するための以下のソフトウェアアップデートをリリースしました: - iMC PLAT 7.3 E0506以降のバージョン