Vulnerabilities > CVE-2014-2623 - Unspecified vulnerability in HP Storage Data Protector 8.0/8.10
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description HP Data Protector 8.10 Remote Command Execution. CVE-2014-2623. Remote exploit for windows platform file exploits/windows/remote/36304.rb id EDB-ID:36304 last seen 2016-02-04 modified 2015-03-06 platform windows port 5555 published 2015-03-06 reporter metasploit source https://www.exploit-db.com/download/36304/ title HP Data Protector 8.10 Remote Command Execution type remote description HP Data Protector 8.x - Remote Command Execution. CVE-2014-2623. Remote exploit for hp-ux platform file exploits/hp-ux/remote/35961.py id EDB-ID:35961 last seen 2016-02-04 modified 2015-01-30 platform hp-ux port published 2015-01-30 reporter Juttikhun Khamchaiyaphum source https://www.exploit-db.com/download/35961/ title HP Data Protector 8.x - Remote Command Execution type remote description HP Data Protector Manager 8.10 - Remote Command Execution. CVE-2014-2623. Remote exploit for windows platform file exploits/windows/remote/34066.py id EDB-ID:34066 last seen 2016-02-03 modified 2014-07-14 platform windows port published 2014-07-14 reporter Polunchis source https://www.exploit-db.com/download/34066/ title HP Data Protector Manager 8.10 - Remote Command Execution type remote
Metasploit
description | This module exploits a remote command execution on HP Data Protector 8.10. Arbitrary commands can be executed by sending crafted requests with opcode 28 to the OmniInet service listening on the TCP/5555 port. Since there is a strict length limitation on the command, rundll32.exe is executed, and the payload is provided through a DLL by a fake SMB server. This module has been tested successfully on HP Data Protector 8.1 on Windows 7 SP1. |
id | MSF:EXPLOIT/WINDOWS/MISC/HP_DATAPROTECTOR_CMD_EXEC |
last seen | 2020-06-05 |
modified | 2017-09-14 |
published | 2015-03-04 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/misc/hp_dataprotector_cmd_exec.rb |
title | HP Data Protector 8.10 Remote Command Execution |
Packetstorm
data source | https://packetstormsecurity.com/files/download/130658/hp_dataprotector_cmd_exec.rb.txt |
id | PACKETSTORM:130658 |
last seen | 2016-12-05 |
published | 2015-03-05 |
reporter | Christian Ramirez |
source | https://packetstormsecurity.com/files/130658/HP-Data-Protector-8.10-Remote-Command-Execution.html |
title | HP Data Protector 8.10 Remote Command Execution |
Saint
bid 68672 description HP Data Protector Unauthenticated Remote Code Execution id net_openview_hpdataprot osvdb 109069 title hp_data_protector_tesertest type remote bid 68672 description HP Data Protector Windows Unauthenticated Remote Code Execution id net_openview_hpdataprot osvdb 109069 title hp_data_protector_perl type remote
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:89446 |
last seen | 2017-11-19 |
modified | 2015-09-17 |
published | 2015-09-17 |
source | https://www.seebug.org/vuldb/ssvid-89446 |
title | HP Data Protector 8.x - Remote Command Execution |
References
- http://packetstormsecurity.com/files/130658/HP-Data-Protector-8.10-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/130658/HP-Data-Protector-8.10-Remote-Command-Execution.html
- http://www.exploit-db.com/exploits/34066/
- http://www.exploit-db.com/exploits/34066/
- http://www.exploit-db.com/exploits/35961
- http://www.exploit-db.com/exploits/35961
- http://www.exploit-db.com/exploits/36304
- http://www.exploit-db.com/exploits/36304
- http://www.osvdb.org/109069
- http://www.osvdb.org/109069
- http://www.securitytracker.com/id/1030583
- http://www.securitytracker.com/id/1030583
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04373818
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04373818
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04373818
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04373818