EXPOSURES › CVE-2013-4810
CVE-2013-4810
HIGH ⌖ ON CISA KEV · EXPLOITEDHP ProCurve Manager and related products suffered a remote code execution vulnerability that was actively exploited in the wild.
A remote code execution flaw in HP ProCurve Manager and related management products allowed attackers to execute arbitrary code via a marshalled object. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability that could lead to full system compromise and violates CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must ensure all HP management software is updated to patched versions and monitor for similar unpatched CVEs in their supply chain.
Shame score — The vulnerability was actively exploited in the wild and remained unpatched for years, demonstrating severe negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.