Database/Control plane, storage & DevOps
HPE Insight Remote Support (directory traversal to RCE): Directory traversal allowing unauthenticated remote code
CVE-2024-53676Control plane, storage & DevOpscurated
Impact
Directory traversal allowing unauthenticated remote code execution. Public proof-of-concept code exists, and this one has seen real-world exploitation attention - treat it as actively targeted.
Who can reach it
Unauthenticated network access to Insight RS.
What to do
Patch per HPESBGN04731 without waiting for a maintenance window. If IRS was exposed, hunt for webshells and unexpected files under the application directories before declaring it clean.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.