CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
Percentile
99.6%
Added: 10/30/2013
CVE: CVE-2013-2367
BID: 61506
OSVDB: 95824
HP SiteScope is an agentless software application used to monitor the availability and performance of distributed IT infrastructures including servers, operating systems, network and Internet services, applications and application components.
HP SiteScope is vulnerable to remote code execution because the runOMAgentCommand in an APIBSMIntegrationImpl SOAP request does not properly sanitize user-supplied input. By supplying a windows shell command to the omHost key, an attacker can execute arbitrary commands with SYSTEM privileges.
Upgrade to SiteScope v11.22 or higher.
<http://www.zerodayinitiative.com/advisories/ZDI-13-205/>
This exploit was tested against HP SiteScope 11.20 on Windows Server 2003 SP2 English (DEP OptOut) and Windows Server 2008 SP2 (DEP OptOut).
Windows