Back
CVE-2016-2004
CRITICAL
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.
Published: Apr 21, 2016
Modified: May 6, 2026
CWE-306
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| hp | data_protector | * ≥ 7.0 < 7.03_108 |
| hp | data_protector | * ≥ 8.0 < 8.15 |
| hp | data_protector | * ≥ 9.0 < 9.06 |
References (14)
- http://packetstormsecurity.com/files/137199/HP-Data-Protector-A.09.00-Command-Execution.html Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137341/HP-Data-Protector-Encrypted-Communication-Remote-Command-Execution.html Exploit, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/267328 Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1035631 Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988 Vendor Advisory
- https://www.exploit-db.com/exploits/39858/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39874/ Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137199/HP-Data-Protector-A.09.00-Command-Execution.html Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/137341/HP-Data-Protector-Encrypted-Communication-Remote-Command-Execution.html Exploit, Third Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/267328 Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1035631 Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988 Vendor Advisory
- https://www.exploit-db.com/exploits/39858/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39874/ Exploit, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
92.73%
Top 0% most likely to be exploited
Threat Score
77 / 100
Data Sources
NVD
EPSS