PT-2025-13633 · Hewlett Packard · Hpe Insight Cluster Management Utility

Published

2025-03-30

·

Updated

2025-04-09

·

CVE-2024-13804

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE Insight Cluster Management Utility (CMU) version 8.2
Description The issue affects HPE Insight Cluster Management Utility (CMU) and allows for unauthenticated remote code execution (RCE). This enables attackers to execute commands with root privileges. Immediate mitigation is recommended.
Recommendations For HPE Insight Cluster Management Utility (CMU) version 8.2, consider disabling the vulnerable component until a patch is available. Restrict access to the utility to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-13804

Affected Products

Hpe Insight Cluster Management Utility