Vulnerability record · CVE-2013-2370 · published 29 July 2013
CVE-2013-2370: HP LoadRunner remote code execution via unspecified vectors
Hp · Loadrunner
CVE-2013-2370 is an unspecified vulnerability in HP LoadRunner before 11.52 that allows remote attackers to execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1671. The record gives no root cause, no affected component and no attack details, so defenders cannot reason about the exact flaw from the advisory alone. It matters because unauthenticated remote code execution in a load-testing product can give an attacker a foothold on the host running LoadRunner.
Description
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a high EPSS score warrants prompt patching, though the absence of KEV listing and exploit details keeps it below critical.
What it is
CVE-2013-2370 is an unspecified vulnerability in HP LoadRunner before 11.52 that allows remote attackers to execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1671. The record gives no root cause, no affected component and no attack details, so defenders cannot reason about the exact flaw from the advisory alone. It matters because unauthenticated remote code execution in a load-testing product can give an attacker a foothold on the host running LoadRunner.
Impact
A successful attack lets a remote, unauthenticated attacker execute arbitrary code on the LoadRunner system, with partial impact to confidentiality, integrity and availability per the CVSS 2.0 vector. The record does not state the privilege level the code runs at or what data is reachable.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not identify the protocol, port or component involved, and it does not state whether any user interaction is required.
Exploitation
The record is not listed in CISA KEV and contains no exploit references, so there is no confirmed in-the-wild exploitation. EPSS is high at roughly 0.62 probability over 30 days (99th percentile), which suggests elevated likelihood but is a model estimate, not evidence of active exploitation.
What to do
- Upgrade HP LoadRunner to version 11.52 or later as directed by the vendor advisory.
- If upgrade is not immediately possible, restrict network access to LoadRunner services to trusted hosts and management networks only.
- Place LoadRunner hosts behind firewalls or segmented VLANs and avoid exposing them directly to untrusted networks.
- Monitor the vendor advisory page for updated guidance, since the flaw details are unspecified.
- Review and harden the operating system account and permissions under which LoadRunner services run.
Detection
- Monitor LoadRunner host logs and network traffic for unexpected inbound connections to LoadRunner service ports from untrusted sources.
- Alert on unusual child processes or command execution spawned by LoadRunner service processes.
- Baseline normal LoadRunner controller and agent communication patterns and flag deviations, especially from external IP addresses.
- Watch for exploitation attempts against LoadRunner hosts using IDS/IPS signatures if the vendor or a third party publishes them.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2370 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2370), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.