Vulnerability record · CVE-2007-2280 · published 18 December 2009
CVE-2007-2280: HP OpenView Storage Data Protector OmniInet stack buffer overflow
Hp · Openview Storage Data Protector
OmniInet.exe, the backup client service daemon in HP OpenView Storage Data Protector 5.50 and 6.0, contains a stack-based buffer overflow reachable through an MSG_PROTOCOL command with long arguments. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. It is distinct from CVE-2009-3844.
Description
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network-reachable, unauthenticated remote code execution and very high EPSS make this a top remediation priority despite the absence of KEV listing.
What it is
OmniInet.exe, the backup client service daemon in HP OpenView Storage Data Protector 5.50 and 6.0, contains a stack-based buffer overflow reachable through an MSG_PROTOCOL command with long arguments. A remote, unauthenticated attacker can trigger it and execute arbitrary code on the affected host. It is distinct from CVE-2009-3844.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the OmniInet service, typically with high privileges on the backup server or client. That can lead to full compromise of the host and the backup data it manages.
Attack surface
The flaw is reached over the network via the OmniInet service protocol; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing the Data Protector client service port is a candidate target.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.60286, 99th percentile), indicating substantial predicted exploitation activity. Reference tags only indicate Patch links; no public exploit code is confirmed in the supplied data.
What to do
- Apply the vendor patch for OmniInet referenced in the ZDI-09-099 and SecurityTracker advisories.
- Restrict network access to the OmniInet service port to trusted backup management hosts only.
- Segment backup servers and clients from general user networks and the internet.
- Monitor vendor advisories for the related CVE-2009-3844 and patch both if unaddressed.
- If patching is not possible, disable or firewall the Data Protector client service until it can be updated.
Detection
- Monitor OmniInet service logs for malformed or oversized MSG_PROTOCOL commands.
- Alert on crashes or restarts of OmniInet.exe on Data Protector hosts.
- Use network monitoring to flag unexpected hosts connecting to the OmniInet service port.
- Hunt for unusual child processes spawned by OmniInet.exe on backup servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2280 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2280), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.