Vulnerability record · CVE-2013-2367 · published 31 July 2013
CVE-2013-2367: HP SiteScope SOAP interface remote code execution
Hp · Sitescope
HP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code through unknown vectors. The record gives no detail on the underlying flaw, so the exact defect cannot be confirmed from the advisory alone.
Description
Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication and full code execution impact, combined with a very high EPSS percentile, warrants immediate remediation despite the thin technical detail.
What it is
HP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code through unknown vectors. The record gives no detail on the underlying flaw, so the exact defect cannot be confirmed from the advisory alone.
Impact
A remote attacker can execute arbitrary code on the SiteScope server, which per the CVSS 2.0 vector means full loss of confidentiality, integrity and availability. Successful exploitation would give the attacker control of the monitoring host and any data or credentials it holds.
Attack surface
The vector is network-reachable with no authentication and no user interaction (AV:N/AC:L/Au:N), and the description ties the issue to the SOAP interface. Any host that can reach the SiteScope SOAP endpoint can attempt exploitation.
Exploitation
The CVE is not listed in CISA KEV and no public exploit is referenced, but EPSS is 0.68895 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity. The only references are duplicate HP vendor advisories.
What to do
- Apply the HP vendor advisory fix for SiteScope 11.20 and 11.21, or upgrade to a supported release.
- Restrict network access to the SiteScope SOAP endpoint to trusted management hosts only.
- Disable or block SOAP where it is not operationally required.
- Place SiteScope behind a firewall or reverse proxy that filters requests to the SOAP service.
- Monitor the SiteScope host for unexpected process creation or outbound connections.
Detection
- Review SiteScope SOAP endpoint logs for anomalous or malformed requests, especially from untrusted source IPs.
- Alert on unexpected child processes or command shells spawned by the SiteScope service.
- Monitor for new outbound connections from the SiteScope host to unfamiliar destinations.
- Audit access to the SOAP port and flag any source outside the approved management network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2367 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.