Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Apr 15, 2022

CVE-2013-4810

High
EPSS 89.6%CISA KEV
Hewlett Packard (HP)/ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management

Description

HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet.

EPSS — Exploit Probability

89.6%

Higher than 99.5% of all CVEs

Required Action

https://nvd.nist.gov/vuln/detail/CVE-2013-4810

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
89.6%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Mar 25, 2022

Added to KEV

Mar 25, 2022

Remediation Due

Apr 15, 2022

Affected Product

Hewlett Packard (HP)

ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management

View all Hewlett Packard (HP) CVEs