Vulnerability record · CVE-2013-4798 · published 29 July 2013
CVE-2013-4798: HP LoadRunner remote code execution via unspecified vectors
Hp · Loadrunner
HP LoadRunner before 11.52 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, only that it is remotely reachable and rated 10.0 under CVSS 2.0. Because LoadRunner is a load-testing tool often run with broad privileges, code execution on it can be serious.
Description
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10.0 with network reachability, no authentication and full impact, combined with a high EPSS percentile, warrants critical priority despite the thin description.
What it is
HP LoadRunner before 11.52 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, only that it is remotely reachable and rated 10.0 under CVSS 2.0. Because LoadRunner is a load-testing tool often run with broad privileges, code execution on it can be serious.
Impact
A remote attacker can execute arbitrary code on the LoadRunner host, gaining full control of confidentiality, integrity and availability per the CVSS vector. This can lead to compromise of the testing infrastructure and any credentials or data it handles.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that cannot be confirmed from the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.67 (99th percentile), suggesting elevated likelihood of exploitation activity. No reference is tagged as an exploit, so public exploit availability is not confirmed by the record.
What to do
- Upgrade HP LoadRunner to version 11.52 or later as directed by the vendor advisory.
- Restrict network access to LoadRunner controllers, agents and management interfaces to trusted hosts only.
- Run LoadRunner components with least privilege and isolate them from production networks.
- Monitor the vendor advisory and apply any follow-up patches or configuration guidance.
- If upgrade is not possible, segment and closely monitor affected hosts for anomalous activity.
Detection
- Monitor network traffic to and from LoadRunner hosts for unexpected inbound connections or unusual outbound traffic.
- Alert on unexpected process creation, especially command shells or scripting engines, on LoadRunner servers.
- Review LoadRunner and host logs for unusual authentication or service activity around exposed ports.
- Use file integrity monitoring on LoadRunner installation directories to catch dropped or modified files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4798 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.