← Vulnerability feed

Vulnerability record · CVE-2008-1661 · published 4 June 2008

CVE-2008-1661: HP StorageWorks Storage Mirroring DoubleTake.exe stack buffer overflow

Hp · Storageworks Storage Mirroring

DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 contains a stack-based buffer overflow triggered by a crafted encoded authentication request. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the affected host. The flaw is remotely reachable over the network with no authentication required, making it a serious pre-auth risk for exposed SWSM installations.

10.0 CVSS 2.0 High EPSS 69% · top 0.7% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, combined with a high EPSS probability, warrants critical priority despite the absence of KEV listing.

What it is

DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 contains a stack-based buffer overflow triggered by a crafted encoded authentication request. A remote, unauthenticated attacker can overflow the buffer and potentially execute arbitrary code on the affected host. The flaw is remotely reachable over the network with no authentication required, making it a serious pre-auth risk for exposed SWSM installations.

Impact

Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the DoubleTake.exe service, potentially leading to full compromise of the host. Failed attempts may crash the service, causing a denial of service.

Attack surface

The vulnerability is reached over the network via a crafted encoded authentication request sent to the DoubleTake.exe service, per the AV:N vector. No authentication or user interaction is required (Au:N, AC:L).

Exploitation

The record shows no CISA KEV listing and no ransomware association, but EPSS is high at roughly 0.69 (99th percentile), indicating elevated likelihood of exploitation activity. Reference tags are limited to a vendor advisory with no public exploit or PoC tags present.

What to do

  • Upgrade HP StorageWorks Storage Mirroring to version 4.5 SP2 or later as the primary fix.
  • Restrict network access to the DoubleTake.exe service port to trusted hosts only, blocking exposure to untrusted networks.
  • Segment SWSM hosts from general user networks and the internet where operationally feasible.
  • Monitor vendor advisories for any further patches or updated guidance for SWSM 4.5.
  • If patching is not immediately possible, consider disabling or firewalling the affected service until the upgrade is applied.

Detection

  • Monitor for crashes or abnormal termination of DoubleTake.exe, which may indicate exploitation attempts.
  • Inspect network traffic to the DoubleTake service port for malformed or unusually long encoded authentication requests.
  • Review host logs and process telemetry for unexpected child processes or code execution originating from DoubleTake.exe.
  • Alert on repeated connection attempts to the SWSM service from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1661 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4116Hp storageworks storage mirroring vulnerabilityUnspecified vulnerability in HP StorageWorks Storage Mirroring 5.x before 5.2.2.1771.2 allows remote attackers to execute arbitrary code via unknown …EPSS 12%10.0CVE-2010-1962Hp storageworks storage mirroring vulnerabilityUnspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vec…EPSS 12%10.0CVE-2009-0718Hp storageworks storage mirroring vulnerabilityUnspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to execute arbitrary code via unknown v…EPSS 7.9%7.5CVE-2009-0716Hp storageworks storage mirroring vulnerabilityUnspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service or obtain …EPSS 2.3%5.0CVE-2009-0717Hp storageworks storage mirroring vulnerabilityUnspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service via unknow…EPSS 2.3%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1661), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.