Vulnerability record · CVE-2013-4835 · published 4 November 2013
CVE-2013-4835: HP SiteScope SOAP service auth bypass and remote code execution
Hp · Sitescope
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code through a direct request to the issueSiebelCmd method. Because the flaw is reachable over the network without credentials, it exposes unpatched SiteScope installations to full compromise.
Description
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and a very high EPSS score, though the product is legacy and not in KEV.
What it is
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code through a direct request to the issueSiebelCmd method. Because the flaw is reachable over the network without credentials, it exposes unpatched SiteScope installations to full compromise.
Impact
An unauthenticated attacker can bypass authentication and execute arbitrary code on the SiteScope server, gaining control of the application and its host.
Attack surface
Reached over the network via a direct SOAP request to the issueSiebelCmd method; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
CVE-2013-4835 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.71003 (99.37th percentile), and an Exploit-DB entry (30473) is referenced, indicating public exploit code exists.
What to do
- Upgrade HP SiteScope to version 11.22 or later, which is the fixed release named in the advisory.
- If immediate upgrade is not possible, restrict network access to the SiteScope SOAP service to trusted management hosts only.
- Disable or block the APISiteScopeImpl SOAP endpoint and the issueSiebelCmd method where they are not required.
- Monitor vendor advisory emr_na-c03969435 for any additional guidance or updated fixed versions.
Detection
- Inspect SOAP request logs for direct calls to the issueSiebelCmd method, especially from unexpected source addresses.
- Alert on SiteScope SOAP requests that reach the APISiteScopeImpl service without prior authentication.
- Hunt for unexpected child processes or command execution spawned by the SiteScope service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4835 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4835), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.