CVE-2013-4810
HP Multiple Products Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 79.00% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-94
- Affected
- hp/application lifecycle management · hp/procurve manager
- Source
- hp-security-alert@hp.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2013-4810
References
- http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03897409Broken Link, Vendor Advisory
- http://marc.info/?l=bugtraq&m=138696448823753&w=2Mailing List
- http://marc.info/?l=bugtraq&m=143039425503668&w=2Mailing List
- http://secunia.com/advisories/54788Broken Link, Vendor Advisory
- http://www.securitytracker.com/id/1029010Broken Link, Third Party Advisory, VDB Entry
- http://zerodayinitiative.com/advisories/ZDI-13-229/Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/28713/Exploit, Third Party Advisory, VDB Entry
- http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03897409Broken Link, Vendor Advisory
- http://marc.info/?l=bugtraq&m=138696448823753&w=2Mailing List
- http://marc.info/?l=bugtraq&m=143039425503668&w=2Mailing List
- http://secunia.com/advisories/54788Broken Link, Vendor Advisory
- http://www.securitytracker.com/id/1029010Broken Link, Third Party Advisory, VDB Entry
- http://zerodayinitiative.com/advisories/ZDI-13-229/Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/28713/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-4810US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.