CVE-2013-4812
HP PCM+ SNAC Registration Server UpdateCertificatesServlet Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.
El servlet UpdateCertificatesServlet en el servicio de registro de SNAC en HP ProCurve Manager (PCM) 3.20 y 4.0, PCM+ 3.20 y 4.0, e Identity Driven Manager (IDM) 4.0 no valida apropiadamente el argumento "fileName" lo que permite a atacantes remotos subir ficheros .jsp y en consecuencia ejecutar código arbitrario a través de vectores sin especificar , tambien conocido como ZDI-CAN-1743.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP PCM Plus. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UpdateCertificatesServlet. This servlet improperly sanitizes the 'fileName' argument allowing the remote attacker could upload a .jsp file. This can result in remote code execution under the context of the SYSTEM user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-07-12 CVE Reserved
- 2013-09-10 CVE Published
- 2013-09-17 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/54788 | Third Party Advisory | |
http://www.securitytracker.com/id/1029010 | Vdb Entry | |
http://zerodayinitiative.com/advisories/ZDI-13-225 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28337 | 2013-09-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Identity Driven Manager Search vendor "Hp" for product "Identity Driven Manager" | 4.0 Search vendor "Hp" for product "Identity Driven Manager" and version "4.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 3.20 Search vendor "Hp" for product "Procurve Manager" and version "3.20" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 3.20 Search vendor "Hp" for product "Procurve Manager" and version "3.20" | plus |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 4.0 Search vendor "Hp" for product "Procurve Manager" and version "4.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Procurve Manager Search vendor "Hp" for product "Procurve Manager" | 4.0 Search vendor "Hp" for product "Procurve Manager" and version "4.0" | plus |
Affected
|