CVE-2013-4810

CRITICAL KEV RANSOMWARE

HP ProCurve Manager <4.0 - RCE

Title source: llm

Description

HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpremotephp
https://www.exploit-db.com/exploits/28713

Scores

CVSS v3 9.8
EPSS 0.8970
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-25
VulnCheck KEV 2016-03-25
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2013-4655
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (3)
hp/application_lifecycle_management
hp/procurve_manager 3.20 (2 CPE variants)
hp/procurve_manager 4.0 (2 CPE variants)
Published Sep 16, 2013
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026