The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745.
2013-09-16T13:01:46.237
2025-04-22T14:51:37.563
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hp | identity_driven_manager | 4.0 | Yes |
Application | hp | procurve_manager | 3.20 | Yes |
Application | hp | procurve_manager | 4.0 | Yes |