CVE-2013-4811

critical
Published 2013-09-16 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: hp-security-alert@hp.com — http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03897409

Application impact

VendorProductVersionsFixed
hpidentity_driven_manager4.0
hpprocurve_manager3.20
hpprocurve_manager4.0

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.