← Vulnerability feed

Vulnerability record · CVE-2012-3259 · published 25 September 2012

CVE-2012-3259: HP SiteScope SOAP feature allows remote code execution

Hp · Sitescope

An unspecified flaw in a SOAP feature of HP SiteScope 11.10 through 11.12 lets remote attackers execute arbitrary code. The record gives no root cause, no affected component detail beyond "SOAP feature", and no exploit specifics, so defenders must treat the vendor advisory as the primary source. Because the flaw is remotely reachable and rated 10.0, it is a serious risk for any exposed SiteScope instance.

10.0 CVSS 2.0 High EPSS 60% · top 0.9%
10.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityNetwork-reachable, unauthenticated remote code execution with a 10.0 CVSS score and very high EPSS, though the record lacks exploit and fixed-version detail.

What it is

An unspecified flaw in a SOAP feature of HP SiteScope 11.10 through 11.12 lets remote attackers execute arbitrary code. The record gives no root cause, no affected component detail beyond "SOAP feature", and no exploit specifics, so defenders must treat the vendor advisory as the primary source. Because the flaw is remotely reachable and rated 10.0, it is a serious risk for any exposed SiteScope instance.

Impact

A successful attacker gains arbitrary code execution on the SiteScope server, which typically runs with service-level privileges and holds monitoring credentials and configuration data. That can lead to full compromise of the host and any monitored systems it can reach.

Attack surface

The vector is network-reachable with no authentication required (AV:N/AC:L/Au:N), so the SOAP interface is the entry point. No user interaction is indicated by the description or vector.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged in the record, but EPSS is 0.6022 (99th percentile), indicating a high modeled likelihood of exploitation activity. The vendor advisory is the only substantive reference.

What to do

  • Apply the HP SiteScope update referenced in vendor advisory emr_na-c03489683, or upgrade past the affected 11.10-11.12 range.
  • Restrict network access to the SiteScope SOAP interface to trusted management hosts only.
  • Place SiteScope behind a reverse proxy or firewall rule set that blocks untrusted SOAP traffic.
  • Rotate credentials and secrets stored in or reachable from SiteScope if compromise is suspected.
  • Monitor the vendor advisory for updated fixed-version guidance since the record does not name one.

Detection

  • Review SiteScope SOAP endpoint logs for unexpected or malformed requests, especially from non-management networks.
  • Alert on new or unusual outbound connections and child processes spawned by the SiteScope service.
  • Baseline normal SOAP client sources and flag first-seen source IPs hitting the SOAP interface.
  • Correlate SiteScope host process creation with web server access logs around the same timestamp.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3259 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-2367HP SiteScope SOAP interface remote code executionHP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code t…EPSS 69%analysed10.0CVE-2012-3260Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3261Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3262Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%10.0CVE-2012-3263Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%9.8CVE-2017-14349Hp sitescope improper privilege management vulnerabilityAn authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon…EPSS 2.6%9.4CVE-2013-6207Hp sitescope vulnerabilityUnspecified vulnerability in the loadFileContents function in the SOAP implementation in HP SiteScope 10.1x, 11.1x, and 11.21 allows remote attackers…EPSS 3.4%8.7CVE-2015-2120Hp sitescope vulnerabilityUnspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2012-3259), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.