logo

Hewlett Packard RCE Vulnerability Allows Attackers to Bypass Authentication and Execute Remote Commands

ID: 9a9c6c97-cdf1-55c1-ab3e-6454cd76dea5

STIX ID: report--9a9c6c97-cdf1-55c1-ab3e-6454cd76dea5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Critical unauthenticated RCE (CVE-2024-13804) in HPE Insight Cluster Management Utility v8.2:** Researchers demonstrated that by decompiling and modifying the CMU Java client (cmugui_standalone.jar) attackers can bypass client-side isAdmin checks and use RMI to execute arbitrary commands as root on backend servers (port 1099); the product is EOL and unpatched, increasing risk to exposed HPC environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.