Executive brief
HPE Intelligent Management Center (CPPM) is a network access control and device management platform used by enterprises. An unauthenticated attacker can remotely trigger a denial-of-service condition, causing the management interface to become unstable and degrade performance, disrupting administrative access and network management operations.
Technical details
A denial-of-service vulnerability exists in the web-based management interface of CPPM that does not require authentication to trigger. An attacker on the network can send crafted requests to the management interface to cause instability and performance degradation. The vulnerability allows remote DoS attacks without prior authentication or user interaction, potentially making the device unavailable to administrators and impacting network access control operations.
Affected products
- Hewlett Packard Enterprise Intelligent Management Center (CPPM)
Timeline
- 2026-09-09: disclosed