Vulnerability record · CVE-2013-4810 · published 16 September 2013
CVE-2013-4810: HP ProCurve Manager and IDM Java deserialization remote code execution
Hp · Application Lifecycle Management
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager 4.0, and Application Lifecycle Management accept marshalled objects sent to EJBInvokerServlet or JMXInvokerServlet, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network with no authentication, and it is listed in CISA KEV, so it matters for any organization still running these legacy HP management products.
Description
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, active inclusion in CISA KEV, and a very high EPSS score make this an urgent fix for any exposed instance.
What it is
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager 4.0, and Application Lifecycle Management accept marshalled objects sent to EJBInvokerServlet or JMXInvokerServlet, allowing remote code execution. The flaw is a code injection (CWE-94) reachable over the network with no authentication, and it is listed in CISA KEV, so it matters for any organization still running these legacy HP management products.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected server, gaining full control of the host and any data or credentials it holds.
Attack surface
Reached over the network by sending a crafted marshalled object to the EJBInvokerServlet or JMXInvokerServlet HTTP endpoints. The CVSS vector shows no privileges and no user interaction required, so exposure depends on whether those servlets are reachable.
Exploitation
CVE-2013-4810 is in CISA KEV (added 2022-03-25) and has an EPSS 30-day probability of about 0.79 (99.6th percentile), and a public Exploit-DB entry exists. No ransomware campaign use is documented.
What to do
- Apply the HP vendor updates referenced in the advisory; if no supported fix exists for the installed version, migrate off the affected product.
- Block or restrict network access to EJBInvokerServlet and JMXInvokerServlet, and do not expose these management interfaces to untrusted networks.
- Isolate affected PCM, PCM+, IDM, and Application Lifecycle Management hosts behind firewalls and segmentation.
- Retire or upgrade end-of-life HP management products that no longer receive security fixes.
- Monitor for and investigate any unexpected process execution or outbound connections from these servers.
Detection
- Alert on HTTP requests to EJBInvokerServlet or JMXInvokerServlet, especially POSTs with binary or serialized payloads.
- Monitor for child processes spawned by the Java process hosting these servlets.
- Review network logs for external connections to the management ports used by these products.
- Hunt for known exploitation artifacts or payloads associated with the public Exploit-DB entry for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-4810 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "HP Multiple Products Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4810 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4810), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.