Lucene search

K
cve[email protected]CVE-2013-4812
HistorySep 16, 2013 - 1:01 p.m.

CVE-2013-4812

2013-09-1613:01:46
CWE-20
web.nvd.nist.gov
104
updatecertificatesservlet
hp procurve manager
remote code execution
file upload
vulnerability
cve-2013-4812
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%

UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

Affected configurations

NVD
Node
hpidentity_driven_managerMatch4.0
OR
hpprocurve_managerMatch3.20
OR
hpprocurve_managerMatch3.20plus
OR
hpprocurve_managerMatch4.0
OR
hpprocurve_managerMatch4.0plus

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.962 High

EPSS

Percentile

99.5%