This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.
The remote backup service has multiple vulnerabilities.
According to its version and build number, the remote install of HP
OpenView Data Protector is potentially affected by the following
- Eight buffer overflow vulnerabilities exist in the
application's Backup Client Service (OmniInet.exe),
which could allow an unauthenticated, remote attacker to
execute arbitrary code on the affected host as a
privileged user. Note that these issues only affect HP
Data Protector installs running on Windows.
(CVE-2011-1728, CVE-2011-1729, CVE-2011-1730,
CVE-2011-1731, CVE-2011-1732, CVE-2011-1733,
CVE-2011-1734, and CVE-2011-1735)
- A directory traversal vulnerability exists in the
application's Backup Client Service, which could allow
an unauthenticated, remote attacker to view the contents
of arbitrary files on the affected host. Note that this
issue only affects HP Data Protector installs running
on Windows. (CVE-2011-1736)
- A denial of service vulnerability exists in the
application's Media Management Daemon (mmd) that could
be exploited by an unauthenticated, remote attacker to
crash the affected host. (CVE-2011-2399)
See also :
Apply the relevant patches referenced in HP's advisory (patch A.06.20
or higher). Enable encrypted control communication services.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 7.8
Public Exploit Available : true
Nessus Plugin ID: 53857 ()
Bugtraq ID: 4763848917
CVE ID: CVE-2011-1728CVE-2011-1729CVE-2011-1730CVE-2011-1731CVE-2011-1732CVE-2011-1733CVE-2011-1734CVE-2011-1735CVE-2011-1736CVE-2011-2399
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.