HP Data Protector 'EXEC_INTEGUTIL' Arbitrary Command Execution

Critical Nessus Plugin ID 79233


The remote host is affected by an arbitrary command execution vulnerability.


Nessus was able to execute an operating system command on the remote HP Data Protector installation by sending a specially crafted 'EXEC_INTEGUTIL' packet to the HP Data Protector service.


A patched version is not currently available. As a workaround, enable Encrypted Control Communications (ECC) services on the cell server and all of the clients in the cell.

See Also


Plugin Details

Severity: Critical

ID: 79233

File Name: hp_data_protector_zdi_14_344.nbin

Version: $Revision: 1.20 $

Type: remote

Family: Misc.

Published: 2014/11/13

Modified: 2018/01/29

Dependencies: 11936, 19601

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:U/RC:C

Vulnerability Information

CPE: cpe:/a:hp:storage_data_protector, cpe:/a:hp:data_protector

Required KB Items: Services/data_protector/version

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2014/10/02

Reference Information

BID: 70244

OSVDB: 112582

EDB-ID: 35034