cbcvebase.
CVE-2013-2367
published 2013-07-31

CVE-2013-2367: Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors…

PriorityP276critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
68.89%
99.3th percentile
Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678.

Affected

2 ranges
VendorProductVersion rangeFixed in
hpsitescope
hpsitescope

Detection & IOCsextracted from sources · hover to see the quote

url/SiteScope/services/APIBSMIntegrationImpl
port8080
path/SiteScope/
filenameopcactivate.vbs
  • Alert on HTTP responses containing the 'Apache-Coyote' server banner from HP SiteScope, as the exploit fingerprints this header to confirm a valid target before exploitation
  • Monitor for execution of cscript.exe or WScript.Shell spawning cmd.exe on HP SiteScope Windows hosts, which is the injection chain triggered by the vulnerable opcactivate.vbs script
  • The exploit uses a VBS base64 cmdstager with a line-max of 1500 characters; look for large, chunked VBS payloads delivered over SOAP to the SiteScope service
  • ·Exploitation requires the optional HP Operations Agent component to be installed alongside HP SiteScope, as the vulnerable opcactivate.vbs script is only present when this component is deployed
  • ·The exploit has only been validated against HP SiteScope 11.20 with HP Operations Agent on Windows 2003 SP2; applicability to other OS/version combinations is unconfirmed
  • ·The vulnerability is triggered via SOAP; blocking or restricting unauthenticated access to the APIBSMIntegrationImpl AXIS service endpoint is a key mitigation surface
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.