Performance Center
Vendor:
First CVE: May 7, 2010 · Active for 16 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Performance Center over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2010
16 years ago
Most Recent CVE
Feb 15, 2018
3,081 days ago
CVE Severity & Scoring
Performance Center11 CVEs
18%
45%
36%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (81.8%)
Unknown2 (18.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (72.7%)
High1 (9.1%)
Unknown2 (18.2%)
User Interaction
None6 (54.5%)
Unknown2 (18.2%)
Required3 (27.3%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None7 (63.6%)
Unknown2 (18.2%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1549HIGH Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors. | May 7, 2010 | 10.0 | 85 | NO | YES |
CVE-2017-5789CRITICAL HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner | Oct 11, 2017 | 9.8 | 39 | NO | NO |
CVE-2016-4359CRITICAL Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 throug | Jun 8, 2016 | 9.8 | 36 | NO | NO |
CVE-2016-4360CRITICAL web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 throug | Jun 8, 2016 | 9.1 | 30 | NO | NO |
CVE-2016-4384HIGH HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors. | Sep 21, 2016 | 8.6 | 28 | NO | NO |
CVE-2016-4382HIGH HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user valid | Sep 21, 2016 | 8.3 | 27 | NO | NO |
CVE-2016-8512CRITICAL A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found. | Feb 15, 2018 | 9.8 | 26 | NO | NO |
CVE-2016-4361HIGH HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 1 | Jun 8, 2016 | 7.5 | 26 | NO | NO |
CVE-2015-6857HIGH Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors | Nov 26, 2015 | 7.2 | 25 | NO | NO |
CVE-2017-14359MEDIUM A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting. | Nov 3, 2017 | 5.4 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Performance Center
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.50 | 5 | 8.4 | 7.6% | 0 | 0 |
| 12.20 | 6 | 7.9 | 6.4% | 0 | 0 |
| 12.01 | 5 | 8.4 | 7.6% | 0 | 0 |
| 12.00 | 5 | 8.4 | 7.6% | 0 | 0 |
| 11.52 | 5 | 8.4 | 7.6% | 0 | 0 |