peter bassill · operator
$ cve CVE-2013-4810 JSON

CVE-2013-4810 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 79.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS79.47% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2013-09-16
Last modified2026-06-16

CISA KEV

NameHP Multiple Products Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productHewlett Packard (HP) / ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management
Ransomware usenone reported

Affected (2)

VendorProduct
hpapplication lifecycle management
hpprocurve manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD