HP Data Protector Opcode 28 and 11 Command Execution (CVE-2014-2623)

A command execution vulnerability exists in Hewlett-Packard Data Protector. The vulnerability is due to a design weakness when handling requests to port 5555. A remote attacker can exploit this vulnerability by sending crafted packets to the target service. Successful exploitation could lead to arbitrary command execution with system privileges on the target server.

Leave a Reply