← Vulnerability feed

Vulnerability record · CVE-2011-0922 · published 9 February 2011

CVE-2011-0922: HP Data Protector client remote code execution via EXEC_SETUP UNC path

Hp · Data Protector

The HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attackers to execute arbitrary programs. Because the client accepts this command without authentication, an attacker who can reach the client can run code in its context. The flaw is a classic improper input validation issue in a backup product that often runs with elevated privileges.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated arbitrary code execution and a very high EPSS percentile make this a top remediation priority despite no KEV listing.

What it is

The HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attackers to execute arbitrary programs. Because the client accepts this command without authentication, an attacker who can reach the client can run code in its context. The flaw is a classic improper input validation issue in a backup product that often runs with elevated privileges.

Impact

An attacker gains arbitrary code execution on the affected client, with the CVSS 2.0 vector indicating complete loss of confidentiality, integrity and availability. In practice this can mean full control of the host running the Data Protector client.

Attack surface

The vulnerability is network-reachable (AV:N) with low complexity and no authentication required (Au:N), per the CVSS 2.0 vector. No user interaction is indicated by the record; the attack is delivered through an EXEC_SETUP command referencing a UNC share pathname.

Exploitation

The record is not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.64219 (99.19th percentile), indicating elevated likelihood of exploitation activity. Reference tags provide only a vendor advisory and no explicit exploit-availability tag.

What to do

  • Apply the HP Data Protector update referenced in the vendor advisory (VUPEN advisory 2011/0308) as the first action.
  • Restrict network access to Data Protector client and server ports to trusted management hosts only.
  • Block or filter outbound SMB/UNC traffic from Data Protector clients where operationally feasible.
  • Run Data Protector client services with the least privilege necessary rather than administrative rights.
  • Monitor vendor advisories for this product line and retire unsupported Data Protector versions.

Detection

  • Monitor Data Protector client logs for EXEC_SETUP commands referencing UNC paths.
  • Alert on unexpected outbound SMB connections from Data Protector client hosts.
  • Detect new or unusual process creation on Data Protector client hosts, especially child processes of the client service.
  • Review network flows for external hosts reaching Data Protector client ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0922 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0921Hp data protector improper input validation vulnerabilitycrs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, a…EPSS 11%10.0CVE-2011-0923HP Data Protector client EXEC_CMD input validation flaw allows remote code executionThe HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied t…EPSS 81%analysed10.0CVE-2011-0924Hp data protector improper input validation vulnerabilityThe client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute …EPSS 4.6%9.8CVE-2017-5807Hp data protector memory buffer overflow vulnerabilityA Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.EPSS 22%9.8CVE-2016-2008Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 10%9.8CVE-2016-2007Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2006Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2005Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2011-0922), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.