← Vulnerability feed

Vulnerability record · CVE-2013-4822 · published 13 October 2013

CVE-2013-4822: HP Intelligent Management Center remote code execution flaw

Hp · Imc Branch Intelligent Management System Software Module

HP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected versions or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.

10.0 CVSS 2.0 High EPSS 63% · top 0.8%
10.0CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable code execution with full impact and a very high EPSS score, though the lack of technical detail limits targeted detection.

What it is

HP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected versions or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.

Impact

An unauthenticated remote attacker can execute arbitrary code on the affected iMC or BIMS server, gaining full control of the host and any data or downstream systems it manages.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not state which service or port is involved, so the exact entry point is unknown.

Exploitation

The record shows no CISA KEV listing and no exploit-tagged references, but EPSS is 0.62617 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. No public exploit or in-the-wild confirmation is provided.

What to do

  • Apply the HP vendor advisory fix (emr_na-c03943425) or upgrade to a supported iMC/BIMS release.
  • Restrict network access to iMC and BIMS management interfaces to trusted management networks only.
  • Place iMC/BIMS behind a firewall or reverse proxy and block direct internet exposure.
  • Monitor vendor advisories for updated fixed versions since the record does not list affected builds.
  • Segment the iMC/BIMS host from other management infrastructure to limit lateral movement.

Detection

  • Monitor iMC/BIMS server logs and network traffic for unexpected inbound connections to management ports.
  • Alert on unusual child processes or command execution spawned by iMC/BIMS service accounts.
  • Baseline normal iMC/BIMS network peers and flag new external source IPs reaching the service.
  • Watch for post-exploitation behavior such as new admin accounts, web shells or outbound callbacks from the iMC/BIMS host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4822 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-5201HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified …EPSS 64%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3274HP Intelligent Management Center UAM stack buffer overflow via log dataHP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, tr…EPSS 64%analysed10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%10.0CVE-2011-1853Hp intelligent management center improper input validation vulnerabilitytftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2)…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2013-4822), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.