HP Data Protector Backup Agent RCE

high Nessus Plugin ID 22225

Synopsis

The backup service running on the remote host is affected by a remote code execution vulnerability.

Description

The version of HP Data Protector running on the remote host is affected by an unspecified flaw in the backup agent. An unauthenticated, remote attacker can exploit this to execute arbitrary code through the use of unauthorized backup commands.

Solution

Apply the set of patches for HP Data Protector versions 5.10 and 5.50 as referenced in the HP advisory. Alternatively, if this service is not needed, disable it or filter incoming traffic to this port.

See Also

http://www.nessus.org/u?331e9518

Plugin Details

Severity: High

ID: 22225

File Name: hp_data_protector_bypass.nasl

Version: 1.25

Type: combined

Published: 8/14/2006

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:hp:storage_data_protector, cpe:/a:hp:data_protector

Required KB Items: Services/data_protector/version, Services/data_protector/build

Exploit Ease: No known exploits are available

Patch Publication Date: 10/25/2006

Vulnerability Publication Date: 8/10/2006

Reference Information

CVE: CVE-2006-4201

BID: 19495

CERT: 673228

HP: HPSBMA02138, SSRT061184, emr_na-c00742778