Vulnerability record · CVE-2013-3520 · published 17 June 2013
CVE-2013-3520: VMware vCenter Chargeback Manager upload handling allows code execution
Vmware · Vcenter Chargeback Manager
VMware vCenter Chargeback Manager before 2.5.1 does not properly handle uploads, allowing remote attackers to execute arbitrary code via unspecified vectors. The flaw is a code injection issue (CWE-94) reachable over the network without authentication, so an unpatched instance is directly exposed to remote compromise.
Description
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a high EPSS score, tempered by the lack of confirmed exploitation and the age of the affected product.
What it is
VMware vCenter Chargeback Manager before 2.5.1 does not properly handle uploads, allowing remote attackers to execute arbitrary code via unspecified vectors. The flaw is a code injection issue (CWE-94) reachable over the network without authentication, so an unpatched instance is directly exposed to remote compromise.
Impact
An attacker can execute arbitrary code on the affected server, gaining the privileges of the Chargeback Manager service. That yields full control of the application host and any data or credentials it holds.
Attack surface
Reached over the network via the upload functionality, per the AV:N vector; the CVSS 2.0 vector shows Au:N, so no authentication is required. The description does not state whether any user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, which are only vendor advisories. EPSS is high (0.5564, ~99th percentile), indicating elevated predicted likelihood of exploitation despite the absence of confirmed in-the-wild activity.
What to do
- Upgrade vCenter Chargeback Manager to 2.5.1 or later per VMware advisory VMSA-2013-0008.
- If upgrade is not immediately possible, restrict network access to the Chargeback Manager upload interface to trusted hosts only.
- Place the service behind an authenticated reverse proxy or WAF rule that blocks unexpected upload content types and sizes.
- Review and rotate credentials and secrets stored on or reachable from the Chargeback Manager host, since code execution may expose them.
- Monitor the vendor advisory for any updated guidance, as the record gives no further remediation detail.
Detection
- Inspect Chargeback Manager and web server logs for anomalous or unexpected file upload requests, especially from untrusted source IPs.
- Alert on new or unusual child processes spawned by the Chargeback Manager service or its application server.
- Monitor for writes of executable or script files into upload or web-accessible directories.
- Baseline outbound connections from the Chargeback Manager host and alert on new destinations, which may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.vmware.com/security/advisories/VMSA-2013-0008.html | Vendor Advisory |
| http://www.vmware.com/security/advisories/VMSA-2013-0008.html | Vendor Advisory |
Track CVE-2013-3520 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3520), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.