CVE-2016-2004
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 94%
from disclosure to weapon35 days
Published on NVDApr 21
1st PoC+35d
metasploitApr 18
exploitation probability
94%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.
Affected products
n/a · n/apublic PoCs found — 6✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39858exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/39874cve_referencepacketstormsecurity.com/files/137199/HP-Data-Protector-A.09.00-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/137341/HP-Data-Protector-Encrypted-Communication-Remote-Command-Execution.htmlunverifiedcve_referencewww.exploit-db.com/exploits/39858/unverifiedcve_referencewww.exploit-db.com/exploits/39874/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/137199/HP-Data-Protector-A.09.00-Command-Execution.htmlhttp://packetstormsecurity.com/files/137341/HP-Data-Protector-Encrypted-Communication-Remote-Command-Execution.htmlhttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05085988https://www.exploit-db.com/exploits/39858/https://www.exploit-db.com/exploits/39874/http://www.kb.cert.org/vuls/id/267328http://www.securitytracker.com/id/1035631