← Vulnerability feed

Vulnerability record · CVE-2013-2343 · published 2 July 2013

CVE-2013-2343: HP LeftHand Virtual SAN Appliance hydra remote code execution

Hp · Lefthand P4000 Virtual San Appliance

An unspecified vulnerability in the HP LeftHand Virtual SAN Appliance hydra (software before 10.0) allows remote attackers to execute arbitrary code through unknown vectors. The flaw is fully unauthenticated and network-reachable, and the vendor has issued an advisory, so it matters for any organization still running this appliance.

10.0 CVSS 2.0 High EPSS 62% · top 0.9%
10.0CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability.

What it is

An unspecified vulnerability in the HP LeftHand Virtual SAN Appliance hydra (software before 10.0) allows remote attackers to execute arbitrary code through unknown vectors. The flaw is fully unauthenticated and network-reachable, and the vendor has issued an advisory, so it matters for any organization still running this appliance.

Impact

A remote attacker can execute arbitrary code on the appliance, gaining full control of the device and any storage data or credentials it handles.

Attack surface

Reachable over the network with no authentication required, per the AV:N/AC:L/Au:N vector. The description does not identify the specific interface or protocol, so the exact entry point is unknown.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.61813 (99th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Apply the HP vendor advisory fix and upgrade hydra software to version 10.0 or later.
  • If the appliance cannot be patched, isolate it on a dedicated management network and block untrusted access.
  • Restrict network exposure of the appliance to only required management hosts.
  • Monitor vendor advisories for updated guidance since the vulnerability details remain unspecified.

Detection

  • Monitor appliance and management network logs for unexpected inbound connections or anomalous processes.
  • Alert on unusual outbound traffic or new listening services on the appliance.
  • Audit which hosts can reach the appliance and flag any access from outside the management segment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2343 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2013-2343), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.