← Vulnerability feed

Vulnerability record · CVE-2013-4798 · published 29 July 2013

CVE-2013-4798: HP LoadRunner remote code execution via unspecified vectors

Hp · Loadrunner

HP LoadRunner before 11.52 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, only that it is remotely reachable and rated 10.0 under CVSS 2.0. Because LoadRunner is a load-testing tool often run with broad privileges, code execution on it can be serious.

10.0 CVSS 2.0 High EPSS 67% · top 0.7%
10.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10.0 with network reachability, no authentication and full impact, combined with a high EPSS percentile, warrants critical priority despite the thin description.

What it is

HP LoadRunner before 11.52 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, only that it is remotely reachable and rated 10.0 under CVSS 2.0. Because LoadRunner is a load-testing tool often run with broad privileges, code execution on it can be serious.

Impact

A remote attacker can execute arbitrary code on the LoadRunner host, gaining full control of confidentiality, integrity and availability per the CVSS vector. This can lead to compromise of the testing infrastructure and any credentials or data it handles.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, so that cannot be confirmed from the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.67 (99th percentile), suggesting elevated likelihood of exploitation activity. No reference is tagged as an exploit, so public exploit availability is not confirmed by the record.

What to do

  • Upgrade HP LoadRunner to version 11.52 or later as directed by the vendor advisory.
  • Restrict network access to LoadRunner controllers, agents and management interfaces to trusted hosts only.
  • Run LoadRunner components with least privilege and isolate them from production networks.
  • Monitor the vendor advisory and apply any follow-up patches or configuration guidance.
  • If upgrade is not possible, segment and closely monitor affected hosts for anomalous activity.

Detection

  • Monitor network traffic to and from LoadRunner hosts for unexpected inbound connections or unusual outbound traffic.
  • Alert on unexpected process creation, especially command shells or scripting engines, on LoadRunner servers.
  • Review LoadRunner and host logs for unusual authentication or service activity around exposed ports.
  • Use file integrity monitoring on LoadRunner installation directories to catch dropped or modified files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-2110Hp loadrunner memory buffer overflow vulnerabilityBuffer overflow in HP LoadRunner 11.52 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 11%10.0CVE-2013-6213Hp loadrunner vulnerabilityUnspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unkno…EPSS 11%10.0CVE-2013-4837HP LoadRunner Virtual User Generator remote code executionHP LoadRunner before 11.52 contains an unspecified vulnerability in the Virtual User Generator component that allows remote code execution. The flaw …EPSS 63%analysed10.0CVE-2013-4838Hp loadrunner vulnerabilityUnspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vecto…EPSS 11%10.0CVE-2011-0272Hp loadrunner vulnerabilityUnspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, relat…EPSS 13%10.0CVE-2010-1549HP LoadRunner and Performance Center Agent remote code executionAn unspecified vulnerability in the Agent component of HP LoadRunner and HP Performance Center before 9.50 allows remote attackers to execute arbitra…EPSS 78%analysed9.8CVE-2016-8512Hp loadrunner memory buffer overflow vulnerabilityA Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.EPSS 5.5%9.8CVE-2017-5789Hp loadrunner memory buffer overflow vulnerabilityHPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified …EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2013-4798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.