CVE-2013-4811
HP PCM+ SNAC Registration Server UpdateDomainControllerServlet Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.
UpdateDomainControllerServlet en el servidor de registro SNAC de HP ProCurve Manager (PCM) 3.20 y 4.0, PCM+ 3.20 y 4.0 e Identity Driven Manager (IDM) 4.0 no valida apropiadamente el argumento adCert, lo que permite a atacantes remotos cargar archivos .jsp y consecuentemente ejecutar código a discrección a través de vectores no especificados, tambien conocido como ZDI-CAN-1743.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UpdateDomainControllerServlet. This servlet improperly sanitizes the 'adCert' argument allowing the remote attacker could upload a .jsp file. This can result in remote code execution under the context of the SYSTEM user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-07-12 CVE Reserved
- 2013-09-10 CVE Published
- 2013-09-17 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/54788 | Third Party Advisory | |
http://www.securitytracker.com/id/1029010 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-13-226 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28336 | 2013-09-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Identity Driven Manager Search vendor "Hp" for product "Identity Driven Manager" | 4.0 Search vendor "Hp" for product "Identity Driven Manager" and version "4.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 3.20 Search vendor "Hp" for product "Procurve Manager" and version "3.20" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 3.20 Search vendor "Hp" for product "Procurve Manager" and version "3.20" | plus |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 4.0 Search vendor "Hp" for product "Procurve Manager" and version "4.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 4.0 Search vendor "Hp" for product "Procurve Manager" and version "4.0" | plus |
Affected
|