CVE-2010-1549 describes an unspecified vulnerability in the Agent component of HP LoadRunner before version 9.50 and HP Performance Center before version 9.50, allowing remote attackers to execute arbitrary code. This critical vulnerability has a CVSS score of 10.0, indicating a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Metasploit module exists for remote command execution, and its EPSS score is exceptionally high, suggesting a significant likelihood of exploitation. Despite the high technical risk, there is no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.10CPE matchmatch criteria | cpe:2.3:a:hp:loadrunner:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:hp:loadrunner:7.0:*:*:*:*:*:*:* | ||
7.02CPE matchmatch criteria | cpe:2.3:a:hp:loadrunner:7.02:*:*:*:*:*:*:* | ||
7.5CPE matchmatch criteria | cpe:2.3:a:hp:loadrunner:7.5:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:a:hp:loadrunner:7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
May 5, 2010HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
May 5, 2010HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
May 5, 2010HP Mercury LoadRunner Agent magentproc.exe Remote Arbitrary Code Execution
May 5, 2010