Vulnerability record · CVE-2008-1661 · published 4 June 2008
CVE-2008-1661: HP StorageWorks Storage Mirroring DoubleTake.exe stack buffer overflow
Hp · Storageworks Storage Mirroring
DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 contains a stack-based buffer overflow triggered by a crafted encoded authentication request. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the affected host. The flaw is remotely reachable over the network with no authentication required, making it a serious pre-auth risk for exposed SWSM installations.
Description
Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, combined with a high EPSS probability, warrants critical priority despite the absence of KEV listing.
What it is
DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 contains a stack-based buffer overflow triggered by a crafted encoded authentication request. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the affected host. The flaw is remotely reachable over the network with no authentication required, making it a serious pre-auth risk for exposed SWSM installations.
Impact
Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the DoubleTake.exe service, potentially leading to full compromise of the host. Failed attempts may crash the service, causing a denial of service.
Attack surface
The vulnerability is reached over the network via a crafted encoded authentication request sent to the DoubleTake.exe service, per the AV:N vector. No authentication or user interaction is required (Au:N, AC:L).
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are limited to a vendor advisory with no public exploit or PoC tags present.
What to do
- Upgrade HP StorageWorks Storage Mirroring to version 4.5 SP2 or later as the primary fix.
- Restrict network access to the DoubleTake.exe service port to trusted hosts only, blocking exposure to untrusted networks.
- Segment SWSM hosts from general user networks and the internet where operationally feasible.
- Monitor vendor advisories for any further patches or updated guidance for SWSM 4.5.
- If patching is not immediately possible, consider disabling or firewalling the affected service until the upgrade is applied.
Detection
- Monitor for crashes or abnormal termination of DoubleTake.exe, which may indicate exploitation attempts.
- Inspect network traffic to the DoubleTake service port for malformed or unusually long encoded authentication requests.
- Review host logs and process telemetry for unexpected child processes or code execution originating from DoubleTake.exe.
- Alert on repeated connection attempts to the SWSM service from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1661 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.