← Vulnerability feed

Vulnerability record · CVE-2013-4835 · published 4 November 2013

CVE-2013-4835: HP SiteScope SOAP service auth bypass and remote code execution

Hp · Sitescope

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code through a direct request to the issueSiebelCmd method. Because the flaw is reachable over the network without credentials, it exposes unpatched SiteScope installations to full compromise.

7.5 CVSS 2.0 High EPSS 71% · top 0.6%
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and a very high EPSS score, though the product is legacy and not in KEV.

What it is

The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code through a direct request to the issueSiebelCmd method. Because the flaw is reachable over the network without credentials, it exposes unpatched SiteScope installations to full compromise.

Impact

An unauthenticated attacker can bypass authentication and execute arbitrary code on the SiteScope server, gaining control of the application and its host.

Attack surface

Reached over the network via a direct SOAP request to the issueSiebelCmd method; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

CVE-2013-4835 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.71003 (99.37th percentile), and an Exploit-DB entry (30473) is referenced, indicating public exploit code exists.

What to do

  • Upgrade HP SiteScope to version 11.22 or later, which is the fixed release named in the advisory.
  • If immediate upgrade is not possible, restrict network access to the SiteScope SOAP service to trusted management hosts only.
  • Disable or block the APISiteScopeImpl SOAP endpoint and the issueSiebelCmd method where they are not required.
  • Monitor vendor advisory emr_na-c03969435 for any additional guidance or updated fixed versions.

Detection

  • Inspect SOAP request logs for direct calls to the issueSiebelCmd method, especially from unexpected source addresses.
  • Alert on SiteScope SOAP requests that reach the APISiteScopeImpl service without prior authentication.
  • Hunt for unexpected child processes or command execution spawned by the SiteScope service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4835 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-2367HP SiteScope SOAP interface remote code executionHP SiteScope 11.20 and 11.21 contain multiple unspecified vulnerabilities that, when SOAP is used, allow remote attackers to execute arbitrary code t…EPSS 69%analysed10.0CVE-2012-3259HP SiteScope SOAP feature allows remote code executionAn unspecified flaw in a SOAP feature of HP SiteScope 11.10 through 11.12 lets remote attackers execute arbitrary code. The record gives no root caus…EPSS 60%analysed10.0CVE-2012-3260Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3261Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 40%10.0CVE-2012-3262Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%10.0CVE-2012-3263Hp sitescope vulnerabilityUnspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors…EPSS 8.6%9.8CVE-2017-14349Hp sitescope improper privilege management vulnerabilityAn authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and mon…EPSS 2.6%9.4CVE-2013-6207Hp sitescope vulnerabilityUnspecified vulnerability in the loadFileContents function in the SOAP implementation in HP SiteScope 10.1x, 11.1x, and 11.21 allows remote attackers…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2013-4835), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.