CVE-2024-13804
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 30, 2025
Updated: Apr 1, 2025
CWE ID 287
Summary
CVE-2024-13804 is an unauthenticated Remote Code Execution (RCE) vulnerability affecting HPE Insight Cluster Management Utility. An attacker can exploit this flaw to gain control of affected systems without requiring valid credentials. Successful exploitation allows the attacker to execute arbitrary code and potentially take full control of the targeted environment, posing a serious threat to data confidentiality and system integrity. HPE strongly advises users to update their software to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.