Vulnerability record · CVE-2009-3844 · published 8 December 2009
CVE-2009-3844: HP OpenView Data Protector OmniInet stack buffer overflow
Hp · Openview Data Protector Application Recovery Manager
The OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 contains a stack-based buffer overflow (CWE-119) triggered by a crafted MSG_PROTOCOL packet. A remote, unauthenticated attacker can send such a packet to execute arbitrary code or crash the service, making this a full-impact network flaw.
Description
Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted MSG_PROTOCOL packet.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, plus very high EPSS and an exploit-tagged advisory.
What it is
The OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 contains a stack-based buffer overflow (CWE-119) triggered by a crafted MSG_PROTOCOL packet. A remote, unauthenticated attacker can send such a packet to execute arbitrary code or crash the service, making this a full-impact network flaw.
Impact
Successful exploitation allows arbitrary code execution in the context of the OmniInet service, or a denial of service if code execution fails. Given the CVSS 2.0 vector (C:C/I:C/A:C), the attacker gains complete confidentiality, integrity and availability impact on the affected host.
Attack surface
Reachable over the network via the OmniInet protocol; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can reach the OmniInet listener can deliver the crafted MSG_PROTOCOL packet.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.74063, 99.46th percentile) and a Zero Day Initiative advisory is tagged Exploit, indicating public exploit-related material exists, though the record does not confirm in-the-wild use.
What to do
- Apply the HP vendor patch or upgrade to a fixed Data Protector Application Recovery Manager release; this is the primary action.
- If patching is not immediately possible, restrict network access to the OmniInet port to trusted management hosts only.
- Segment backup and recovery infrastructure from general user and internet-facing networks.
- Monitor HP and ZDI advisories for updated fixed-version guidance, since the record does not list specific patched versions.
Detection
- Monitor OmniInet service logs and host logs for crashes or abnormal termination of the OmniInet process.
- Alert on unexpected or malformed MSG_PROTOCOL traffic to the OmniInet listener, especially from hosts outside the backup management subnet.
- Use network IDS/IPS signatures for the OmniInet protocol to flag oversized or malformed packets.
- Watch for post-exploitation behavior on backup servers, such as new processes spawned by OmniInet or outbound connections from those hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3844 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3844), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.