← Vulnerability feed

Vulnerability record · CVE-2013-2370 · published 29 July 2013

CVE-2013-2370: HP LoadRunner remote code execution via unspecified vectors

Hp · Loadrunner

CVE-2013-2370 is an unspecified vulnerability in HP LoadRunner before 11.52 that allows remote attackers to execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1671. The record gives no root cause, no affected component and no attack details, so defenders cannot reason about the exact flaw from the advisory alone. It matters because unauthenticated remote code execution in a load-testing product can give an attacker a foothold on the host running LoadRunner.

7.5 CVSS 2.0 High EPSS 62% · top 0.8%
7.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: low.

high priorityUnauthenticated remote code execution with a high EPSS score warrants prompt patching, though the absence of KEV listing and exploit details keeps it below critical.

What it is

CVE-2013-2370 is an unspecified vulnerability in HP LoadRunner before 11.52 that allows remote attackers to execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1671. The record gives no root cause, no affected component and no attack details, so defenders cannot reason about the exact flaw from the advisory alone. It matters because unauthenticated remote code execution in a load-testing product can give an attacker a foothold on the host running LoadRunner.

Impact

A successful attack lets a remote, unauthenticated attacker execute arbitrary code on the LoadRunner system, with partial impact to confidentiality, integrity and availability per the CVSS 2.0 vector. The record does not state the privilege level the code runs at or what data is reachable.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not identify the protocol, port or component involved, and it does not state whether any user interaction is required.

Exploitation

The record is not listed in CISA KEV and contains no exploit references, so there is no confirmed in-the-wild exploitation. EPSS is high at roughly 0.62 probability over 30 days (99th percentile), which suggests elevated likelihood but is a model estimate, not evidence of active exploitation.

What to do

  • Upgrade HP LoadRunner to version 11.52 or later as directed by the vendor advisory.
  • If upgrade is not immediately possible, restrict network access to LoadRunner services to trusted hosts and management networks only.
  • Place LoadRunner hosts behind firewalls or segmented VLANs and avoid exposing them directly to untrusted networks.
  • Monitor the vendor advisory page for updated guidance, since the flaw details are unspecified.
  • Review and harden the operating system account and permissions under which LoadRunner services run.

Detection

  • Monitor LoadRunner host logs and network traffic for unexpected inbound connections to LoadRunner service ports from untrusted sources.
  • Alert on unusual child processes or command execution spawned by LoadRunner service processes.
  • Baseline normal LoadRunner controller and agent communication patterns and flag deviations, especially from external IP addresses.
  • Watch for exploitation attempts against LoadRunner hosts using IDS/IPS signatures if the vendor or a third party publishes them.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2370 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-2110Hp loadrunner memory buffer overflow vulnerabilityBuffer overflow in HP LoadRunner 11.52 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 11%10.0CVE-2013-6213Hp loadrunner vulnerabilityUnspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unkno…EPSS 11%10.0CVE-2013-4837HP LoadRunner Virtual User Generator remote code executionHP LoadRunner before 11.52 contains an unspecified vulnerability in the Virtual User Generator component that allows remote code execution. The flaw …EPSS 63%analysed10.0CVE-2013-4838Hp loadrunner vulnerabilityUnspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vecto…EPSS 11%10.0CVE-2013-4798HP LoadRunner remote code execution via unspecified vectorsHP LoadRunner before 11.52 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The record gives no detail o…EPSS 67%analysed10.0CVE-2011-0272Hp loadrunner vulnerabilityUnspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, relat…EPSS 13%10.0CVE-2010-1549HP LoadRunner and Performance Center Agent remote code executionAn unspecified vulnerability in the Agent component of HP LoadRunner and HP Performance Center before 9.50 allows remote attackers to execute arbitra…EPSS 78%analysed9.8CVE-2016-8512Hp loadrunner memory buffer overflow vulnerabilityA Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.EPSS 5.5%

Source: NIST National Vulnerability Database (record CVE-2013-2370), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.