Remote Code Execution Vulnerability in HP ProCurve Manager and IDM
CVE-2013-4812

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
16 September 2013

Summary

The UpdateCertificatesServlet in HP ProCurve Manager (PCM) and Identity Driven Manager (IDM) fails to adequately validate the fileName argument, which allows attackers to upload potentially malicious .jsp files. This vulnerability enables attackers to execute arbitrary code on the affected server, leading to severe security risks. Systems running HP ProCurve Manager versions 3.20 and 4.0, as well as the PCM+ variant and IDM 4.0, are susceptible to exploitation. Regular updates and following security advisories are essential to mitigate these risks.

References

EPSS Score

68% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.