VulnerabilityModified
CVE-2011-1866
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.
HIGH 10.0EPSS 20.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitrary code via a crafted request, related to the EXEC_CMD functionality.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 20.89% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- hp/openview storage data protector
- Source
- hp-security-alert@hp.com
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02872182Vendor Advisory
- http://secunia.com/advisories/45100Vendor Advisory
- http://securityreason.com/securityalert/8289
- http://securitytracker.com/id?1025731
- http://www.coresecurity.com/content/HP-Data-Protector-EXECCMD-VulnerabilityExploit
- http://www.exploit-db.com/exploits/17461
- http://www.securityfocus.com/archive/1/518666/100/0/threaded
- http://www.securityfocus.com/bid/48488
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68297
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02872182Vendor Advisory
- http://secunia.com/advisories/45100Vendor Advisory
- http://securityreason.com/securityalert/8289
- http://securitytracker.com/id?1025731
- http://www.coresecurity.com/content/HP-Data-Protector-EXECCMD-VulnerabilityExploit
- http://www.exploit-db.com/exploits/17461
- http://www.securityfocus.com/archive/1/518666/100/0/threaded
- http://www.securityfocus.com/bid/48488
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68297
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.