CVE-2013-4835

HP SiteScope 10.1x and 11.x < 11.22 - Unauthenticated Remote Code Execution via APISiteScopeImpl issueSiebelCmd Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-4835. PoCs published by Metasploit, including Metasploit module exploits/multi/http/hp_sitescope_issuesiebelcmd.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote code execution vulnerability in HP SiteScope's APISiteScopeImpl web service via the issueSiebelCmd method. It supports both Windows and Linux targets, delivering payloads through SOAP requests.

Description

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteunix
https://www.exploit-db.com/exploits/30473

This Metasploit module exploits an unauthenticated remote code execution vulnerability in HP SiteScope's APISiteScopeImpl web service via the issueSiebelCmd method. It supports both Windows and Linux targets, delivering payloads through SOAP requests.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP SiteScope 11.20
No auth needed
Prerequisites: Network access to the target's SOAP endpoint (port 8080 by default) · Vulnerable HP SiteScope version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/hp_sitescope_issuesiebelcmd.rb

This Metasploit module exploits an unauthenticated remote code execution vulnerability in HP SiteScope's APISiteScopeImpl web service via the issueSiebelCmd method. It supports both Windows and Linux targets, using a SOAP-based command injection technique.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP SiteScope 11.20
No auth needed
Prerequisites: Network access to the target's SOAP endpoint (port 8080 by default) · Vulnerable HP SiteScope version (11.20)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/30473

Scores

EPSS 0.7100
EPSS Percentile 99.3%

Details

Status published
Products (9)
hp/sitescope 10.11
hp/sitescope 10.13
hp/sitescope 11.01
hp/sitescope 11.1
hp/sitescope 11.10
hp/sitescope 11.11
hp/sitescope 11.12
hp/sitescope 11.20
hp/sitescope 11.21
Published Nov 04, 2013
Tracked Since Feb 18, 2026