CVE-2013-4824
HP Intelligent Management Center and IMC Service Operation Management Software Module - Authentication Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-4824.
Includes Metasploit module auxiliary/admin/hp/hp_imc_som_create_account.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass in HP Intelligent Management Center's SOM component to create a privileged account via unauthenticated RPC calls. It leverages GWT serialization to craft a payload that adds an account with administrative permissions.
Description
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.
Exploits (1)
This Metasploit module exploits an authentication bypass in HP Intelligent Management Center's SOM component to create a privileged account via unauthenticated RPC calls. It leverages GWT serialization to craft a payload that adds an account with administrative permissions.