← Vulnerability feed

Vulnerability record · CVE-2007-2280 · published 18 December 2009

CVE-2007-2280: HP OpenView Storage Data Protector OmniInet stack buffer overflow

Hp · Openview Storage Data Protector

OmniInet.exe, the backup client service daemon in HP OpenView Storage Data Protector 5.50 and 6.0, contains a stack-based buffer overflow reachable through an MSG_PROTOCOL command with long arguments. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. It is distinct from CVE-2009-3844.

10.0 CVSS 2.0 High EPSS 60% · top 0.9% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network-reachable, unauthenticated remote code execution and very high EPSS make this a top remediation priority despite the absence of KEV listing.

What it is

OmniInet.exe, the backup client service daemon in HP OpenView Storage Data Protector 5.50 and 6.0, contains a stack-based buffer overflow reachable through an MSG_PROTOCOL command with long arguments. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. It is distinct from CVE-2009-3844.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the OmniInet service, typically with high privileges on the backup server or client. That can lead to full compromise of the host and the backup data it manages.

Attack surface

The flaw is reached over the network via the OmniInet service protocol; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing the Data Protector client service port is a candidate target.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.60286, 99th percentile), indicating substantial predicted exploitation activity. Reference tags only indicate Patch links; no public exploit code is confirmed in the supplied data.

What to do

  • Apply the vendor patch for OmniInet referenced in the ZDI-09-099 and SecurityTracker advisories.
  • Restrict network access to the OmniInet service port to trusted backup management hosts only.
  • Segment backup servers and clients from general user networks and the internet.
  • Monitor vendor advisories for the related CVE-2009-3844 and patch both if unaddressed.
  • If patching is not possible, disable or firewall the Data Protector client service until it can be updated.

Detection

  • Monitor OmniInet service logs for malformed or oversized MSG_PROTOCOL commands.
  • Alert on crashes or restarts of OmniInet.exe on Data Protector hosts.
  • Use network monitoring to flag unexpected hosts connecting to the OmniInet service port.
  • Hunt for unusual child processes spawned by OmniInet.exe on backup servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2280 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-1865HP OpenView Storage Data Protector inet service stack buffer overflowThe inet service in HP OpenView Storage Data Protector 6.00 through 6.20 contains multiple stack-based buffer overflows that can be triggered by a re…EPSS 89%analysed10.0CVE-2011-1866Hp openview storage data protector memory buffer overflow vulnerabilityBuffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remote attackers to execute arbitr…EPSS 21%10.0CVE-2011-1728Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 14%10.0CVE-2011-1729Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 14%10.0CVE-2011-1730Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 14%10.0CVE-2011-1731Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 15%10.0CVE-2011-1732Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 25%10.0CVE-2011-1733Hp openview storage data protector memory buffer overflow vulnerabilityStack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote att…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2007-2280), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.