← Vulnerability feed

Vulnerability record · CVE-2013-2367 · published 31 July 2013

CVE-2013-2367: HP SiteScope SOAP interface remote code execution

Hp · Sitescope

HP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code through unknown vectors. The record gives no detail on the underlying flaw, so the exact defect cannot be confirmed from the advisory alone.

10.0 CVSS 2.0 High EPSS 69% · top 0.7%
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication and full code execution impact, combined with a very high EPSS percentile, warrants immediate remediation despite the thin technical detail.

What it is

HP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code through unknown vectors. The record gives no detail on the underlying flaw, so the exact defect cannot be confirmed from the advisory alone.

Impact

A remote attacker can execute arbitrary code on the SiteScope server, which per the CVSS 2.0 vector means full loss of confidentiality, integrity and availability. Successful exploitation would give the attacker control of the monitoring host and any data or credentials it holds.

Attack surface

The vector is network-reachable with no authentication and no user interaction (AV:N/AC:L/Au:N), and the description ties the issue to the SOAP interface. Any host that can reach the SiteScope SOAP endpoint can attempt exploitation.

Exploitation

The CVE is not listed in CISA KEV and no public exploit is referenced, but EPSS is 0.68895 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity. The only references are duplicate HP vendor advisories.

What to do

  • Apply the HP vendor advisory fix for SiteScope 11.20 and 11.21, or upgrade to a supported release.
  • Restrict network access to the SiteScope SOAP endpoint to trusted management hosts only.
  • Disable or block SOAP where it is not operationally required.
  • Place SiteScope behind a firewall or reverse proxy that filters requests to the SOAP service.
  • Monitor the SiteScope host for unexpected process creation or outbound connections.

Detection

  • Review SiteScope SOAP endpoint logs for anomalous or malformed requests, especially from untrusted source IPs.
  • Alert on unexpected child processes or command shells spawned by the SiteScope service.
  • Monitor for new outbound connections from the SiteScope host to unfamiliar destinations.
  • Audit access to the SOAP port and flag any source outside the approved management network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2367 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-3259HP SiteScope SOAP feature allows remote code executionAn unspecified flaw in a SOAP feature of HP SiteScope 11.10 through 11.12 lets remote attackers execute arbitrary code. The record gives no root caus…EPSS 60%analysed10.0CVE-2012-3260Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3261Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3262Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%10.0CVE-2012-3263Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%9.8CVE-2017-14349Hp sitescope improper privilege management vulnerabilityAn authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon…EPSS 2.6%9.4CVE-2013-6207Hp sitescope vulnerabilityUnspecified vulnerability in the loadFileContents function in the SOAP implementation in HP SiteScope 10.1x, 11.1x, and 11.21 allows remote attackers…EPSS 3.4%8.7CVE-2015-2120Hp sitescope vulnerabilityUnspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to…EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2013-2367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.