APP: HP Data Protector Opcode 28 and 11 Command Execution

An command execution vulnerability exists in Hewlett-Packard Data Protector. The vulnerability is due to the a design weakness when handling requests to port 5555. A remote attacker can exploit this vulnerability by sending crafted packets to the target service. Successful exploitation could lead to arbitrary command execution with System privileges on the target server.

Extended Description

Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

Affected Products

Hp storage_data_protector

Short Name
APP:HP-DATA-PRTCTR-OP28-11
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
11 28 CVE-2014-2623 Command Data Execution HP Opcode Protector and bid:68672
Release Date
07/28/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
Port
TCP/5555
False Positive
Unknown
Vendors

Hp

CVSS Score

10.0

Found a potential security threat?