Hewlett Packard RCE Vulnerability Allows Attackers to Bypass Authentication and Execute Remote Commands
ID: 9a9c6c97-cdf1-55c1-ab3e-6454cd76dea5
STIX ID: report--9a9c6c97-cdf1-55c1-ab3e-6454cd76dea5
Feed Name: cybersecurityNews.com
Threat Score
**Critical unauthenticated RCE (CVE-2024-13804) in HPE Insight Cluster Management Utility v8.2:** Researchers demonstrated that by decompiling and modifying the CMU Java client (cmugui_standalone.jar) attackers can bypass client-side isAdmin checks and use RMI to execute arbitrary commands as root on backend servers (port 1099); the product is EOL and unpatched, increasing risk to exposed HPC environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
