CVE-2019-5392 is an information disclosure vulnerability in HPE Intelligent Management Center (IMC) Platform versions prior to 7.3 E0506P09. The vulnerability allows unauthorized access to sensitive information due to improper access controls or exposure of sensitive data within the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python 3 proof-of-concept exploit for CVE-2019-5392. It contains one executable script, CVE-2019-5392.py, and a short README with usage instructions. The script takes three command-line arguments: target IP, target port, and a directory path to query on the remote system. The exploit works over the network by opening a raw TCP socket to the target service, building an ASN.1/BER-encoded message using pyasn1, and prepending a custom binary header consisting of opcode 10001 and the encoded message length. The ASN.1 structure is named DbmanMsg and contains two fields: an integer flag set to 1 and an OctetString containing the attacker-supplied directory path. After sending the packet, the script reads up to 4000 bytes of response data, performs light cleanup with regex/string replacement, and prints what appears to be the contents of the requested directory. Main capability: unauthorized remote directory listing / information disclosure from the vulnerable service. There is no shell payload, persistence, lateral movement, or post-exploitation logic. The code is operational but basic: it requires manual target and path input and simply prints returned data. The repository structure is minimal and purpose-built for exploiting the vulnerability rather than detecting it.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.