Hewlett Packard RCE Vulnerability Let Attackers to Bypass Authentication and Execute Commands Remotely
ID: 7f751b22-2c08-55f9-8e8a-1b532c0a3da2
STIX ID: report--7f751b22-2c08-55f9-8e8a-1b532c0a3da2
Feed Name: Cyber Press
This report describes CVE-2024-13804, a critical design vulnerability in HPE Insight CMU v8.2 that allows attackers to bypass client-side authentication, modify the Java client to unlock administrative functionality, and use Java RMI to execute arbitrary commands with root privileges across HPC management and compute nodes; because CMU is end-of-life and will not receive a patch, the report urges immediate mitigations such as network isolation, stricter access controls, and migration to supported management solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
