CVE-2013-4824

HP Intelligent Management Center and IMC Service Operation Management Software Module - Authentication Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-4824. Includes Metasploit module auxiliary/admin/hp/hp_imc_som_create_account.

AI-analyzed exploit summary This Metasploit module exploits an authentication bypass in HP Intelligent Management Center's SOM component to create a privileged account via unauthenticated RPC calls. It leverages GWT serialization to craft a payload that adds an account with administrative permissions.

Description

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/hp/hp_imc_som_create_account.rb

This Metasploit module exploits an authentication bypass in HP Intelligent Management Center's SOM component to create a privileged account via unauthenticated RPC calls. It leverages GWT serialization to craft a payload that adds an account with administrative permissions.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: HP Intelligent Management Center 5.2 E0401, 5.1 E202 with SOM 5.2 E0401, SOM 5.1 E0201
No auth needed
Prerequisites: Network access to the target's web interface (port 8080) · Target running vulnerable HP IMC version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

EPSS 0.2393
EPSS Percentile 97.5%

Details

CWE
CWE-287
Status published
Products (2)
hp/imc_service_operation_management_software_module
hp/intelligent_management_center
Published Oct 13, 2013
Tracked Since Feb 18, 2026