CVE-2014-2623
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 89%
from disclosure to weapon0 days
Published on NVDJul 18
1st PoCJul 14
metasploit+107d
VulnCheck+1419d
exploitation probability
89%top 1% of all CVEs
observed exploitation
yesVulnCheck
7 public exploit(s)
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
Affected products
n/a · n/apublic PoCs found — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/35961exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36304exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/34066cve_referencepacketstormsecurity.com/files/130658/HP-Data-Protector-8.10-Remote-Command-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/36304unverifiedcve_referencewww.exploit-db.com/exploits/34066/unverifiedcve_referencewww.exploit-db.com/exploits/35961unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/130658/HP-Data-Protector-8.10-Remote-Command-Execution.htmlhttps://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04373818http://www.exploit-db.com/exploits/34066/http://www.exploit-db.com/exploits/35961http://www.exploit-db.com/exploits/36304http://www.osvdb.org/109069http://www.securitytracker.com/id/1030583