ZeroHour

CVE-2024-53676

large

Unauthenticated Directory Traversal to RCE in HPE Insight Remote Support

CVSS 3.1
9.8 critical
EPSS
56%p99
Published
()
Modified
AI analysis

CVE-2024-53676 is a directory traversal flaw (CWE-22, CWE-552) in HPE Insight Remote Support, HPE's remote monitoring and support service deployed alongside ProLiant server estates, which may allow attackers to escape the intended path restrictions and achieve remote code execution. It is triggered by sending crafted, network-based requests containing traversal sequences to the service, with no authentication required (AV:N/AC:L/PR:N/UI:N). A successful attacker gains code execution on the server hosting Insight Remote Support, with the CVSS score indicating high impact on confidentiality, integrity, and availability. Any organization running HPE Insight Remote Support to monitor HPE ProLiant servers is potentially affected. There is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, but the 56.3% EPSS score (99th percentile) indicates a high likelihood of exploitation attempts within the next 30 days.

What to do: Upgrade Insight Remote Support to the patched release identified in HPE's official security advisory, since no version numbers are provided in the current data. Until patched, restrict network access to the Insight Remote Support service to trusted management networks and confirm it is not exposed to the internet. Because EPSS is high, watch for HPE advisories and monitor the host for unexpected process launches or outbound connections.

Affected
HPE Insight Remote Support
Estimated exposure
largelikely tens of thousands of installations worldwide, with a smaller subset directly internet-exposed — Insight Remote Support is commonly deployed in enterprise data centers running HPE ProLiant servers under support contracts (typically one instance per site managing the local fleet), and HPE's large ProLiant install base suggests a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Vendors
hpe
Products
insight remote support
Weakness
CWE-552, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news