vendor:
Data Protector
by:
Juttikhun Khamchaiyaphum
9.3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Data Protector
Affected Version From: 8.x
Affected Version To: 8.x
Patch Exists: YES
Related CWE: CVE-2014-2623
CPE: a:hewlett_packard:data_protector
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=76616, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/misc/hp_dataprotector_cmd_exec, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=144831
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IA64 HP Server Rx3600
2015
HP-Data-Protector-8.x Remote command execution
HP Data Protector 8.x is vulnerable to remote command execution. An attacker can send a specially crafted packet to the Data Protector service on port 5555/tcp and execute arbitrary commands with root privileges. This vulnerability was discovered by Juttikhun Khamchaiyaphum and was assigned CVE-2014-2623.
Mitigation:
HP has released a patch to address this vulnerability.