CVE-2013-4812
HP ProCurve Manager <4.0 - RCE
Title source: llmDescription
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/28337
metasploit
WORKING POC
EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_pcm_snac_update_certificates.rb
References (4)
Scores
EPSS
0.7400
EPSS Percentile
98.8%
Details
CWE
CWE-20
Status
published
Products (3)
hp/identity_driven_manager
4.0
hp/procurve_manager
3.20
hp/procurve_manager
4.0
Published
Sep 16, 2013
Tracked Since
Feb 18, 2026