VulnerabilityModified
CVE-2013-2347
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.
HIGH 10.0EPSS 66.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 66.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 66.41% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- hp/storage data protector
- Source
- hp-security-alert@hp.com
References
- http://ddilabs.blogspot.com/2014/02/fun-with-hp-data-protector-execbar.htmlPermissions Required
- http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03822422Vendor Advisory
- http://www.exploit-db.com/exploits/32164Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-14-008/Third Party Advisory
- http://ddilabs.blogspot.com/2014/02/fun-with-hp-data-protector-execbar.htmlPermissions Required
- http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03822422Vendor Advisory
- http://www.exploit-db.com/exploits/32164Broken Link
- http://www.zerodayinitiative.com/advisories/ZDI-14-008/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.