← Vulnerability feed

Vulnerability record · CVE-2013-4811 · published 16 September 2013

CVE-2013-4811: HP ProCurve Manager SNAC server adCert validation flaw allows JSP upload and code execution

Hp · Identity Driven Manager

The UpdateDomainControllerServlet in the SNAC registration server of HP ProCurve Manager (PCM) 3.20/4.0, PCM+ 3.20/4.0, and Identity Driven Manager 4.0 fails to properly validate the adCert argument. This lets a remote attacker upload .jsp files to the server and execute arbitrary code. Because the flaw is reachable over the network without authentication and yields full control of the host, it is a serious risk for any exposed deployment.

10.0 CVSS 2.0 High EPSS 71% · top 0.6% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 base score of 10 and a high EPSS probability, though no confirmed in-the-wild exploitation is recorded.

What it is

The UpdateDomainControllerServlet in the SNAC registration server of HP ProCurve Manager (PCM) 3.20/4.0, PCM+ 3.20/4.0, and Identity Driven Manager 4.0 fails to properly validate the adCert argument. This lets a remote attacker upload .jsp files to the server and execute arbitrary code. Because the flaw is reachable over the network without authentication and yields full control of the host, it is a serious risk for any exposed deployment.

Impact

An unauthenticated remote attacker can upload and execute arbitrary JSP code on the SNAC registration server, gaining full control of the affected system (complete confidentiality, integrity, and availability impact per the CVSS vector).

Attack surface

Reachable over the network via the UpdateDomainControllerServlet HTTP endpoint; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.71 (99th percentile), and references include a Zero Day Initiative advisory (ZDI-13-226), indicating public technical detail exists, though the record does not confirm active exploitation.

What to do

  • Apply the HP vendor advisory fix for PCM/PCM+/IDM (emr_na-c03897409) or upgrade to a supported release.
  • Restrict network access to the SNAC registration server so only trusted management hosts can reach it.
  • Block or filter requests to UpdateDomainControllerServlet and reject .jsp uploads at the perimeter or reverse proxy.
  • Run the affected service with least privilege and isolate it from other management infrastructure.
  • If no patch is available, retire or replace the end-of-life product.

Detection

  • Monitor web logs for POST requests to UpdateDomainControllerServlet, especially with adCert parameters or multipart uploads.
  • Alert on newly created .jsp files in web-accessible directories on the SNAC server.
  • Watch for unexpected child processes spawned by the web server or Java service (e.g., cmd.exe, /bin/sh).
  • Review outbound connections from the SNAC host for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4811 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-4810HP ProCurve Manager and IDM Java deserialization remote code executionHP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager 4.0, and Application Lifecycle Management accept marshalled object…KEVEPSS 79%analysed10.0CVE-2013-4812HP ProCurve Manager SNAC servlet file upload leads to RCEUpdateCertificatesServlet in the SNAC registration server of HP ProCurve Manager (PCM) 3.20/4.0, PCM+ 3.20/4.0, and Identity Driven Manager 4.0 fails…EPSS 52%analysed10.0CVE-2013-4813Hp identity driven manager code injection vulnerabilityThe Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows re…EPSS 8.5%7.5CVE-2013-4809Hp identity driven manager sql injection vulnerabilityMultiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager …EPSS 3.3%5.0CVE-2007-4514Hp procurve manager information exposure vulnerabilityUnspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information…EPSS 2.4%9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2013-4811), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.