Vulnerability record · CVE-2011-0514 · published 20 January 2011
CVE-2011-0514: HP Data Protector Manager RDS service buffer overflow denial of service
Hp · Data Protector Manager
The RDS service (rds.exe) in HP Data Protector Manager 6.11 crashes when it receives a packet with a large data size on TCP port 1530. The flaw is classified as a memory buffer overflow (CWE-119), so the same input path could plausibly corrupt memory beyond a simple crash, though the record only documents denial of service.
Description
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash) via a packet with a large data size to TCP port 1530.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityA public exploit and very high EPSS score make exploitation likely, and the flaw is remotely reachable without authentication, though the documented impact is limited to denial of service.
What it is
The RDS service (rds.exe) in HP Data Protector Manager 6.11 crashes when it receives a packet with a large data size on TCP port 1530. The flaw is classified as a memory buffer overflow (CWE-119), so the same input path could plausibly corrupt memory beyond a simple crash, though the record only documents denial of service.
Impact
A remote, unauthenticated attacker can crash the RDS service, disrupting Data Protector Manager operations. The record does not demonstrate code execution or data compromise, so the confirmed impact is availability loss only.
Attack surface
Reachable over the network via a crafted packet to TCP port 1530; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
A public exploit exists on Exploit-DB, and EPSS is 0.48867 (98.8th percentile), indicating elevated likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.
What to do
- Apply the HP vendor patch or upgrade Data Protector Manager beyond the affected 6.11 release; treat this as the first action.
- Restrict access to TCP port 1530 to trusted management hosts using firewall or ACL rules.
- Segment backup and management networks so the RDS service is not reachable from untrusted or general-purpose networks.
- Monitor the RDS service and restart or isolate it if repeated crashes occur.
Detection
- Alert on RDS service (rds.exe) crash or restart events on Data Protector Manager hosts.
- Monitor network traffic to TCP port 1530 for oversized or malformed packets from unexpected sources.
- Baseline which hosts legitimately connect to port 1530 and flag connections from outside that set.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/15940 | Exploit |
| http://www.vupen.com/english/advisories/2011/0064 | Vendor Advisory |
| http://www.exploit-db.com/exploits/15940 | Exploit |
| http://www.vupen.com/english/advisories/2011/0064 | Vendor Advisory |
Track CVE-2011-0514 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0514), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.