vendor:
Data Protector
by:
Adrian Puente Z.
9.3
CVSS
HIGH
Remote Shell
287
CWE
Product Name: Data Protector
Affected Version From: 0.9
Affected Version To: 0.9
Patch Exists: YES
Related CWE: CVE-2011-0923
CPE: a:hp:data_protector
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HPUX
2011
HP Data Protector Remote Shell for HPUX
This exploit allows an attacker to execute arbitrary commands on a vulnerable HP Data Protector system running on HPUX. The vulnerability is due to a lack of authentication when sending specially crafted packets to the Data Protector service. An attacker can exploit this vulnerability to execute arbitrary commands with root privileges.
Mitigation:
HP has released a patch to address this vulnerability.