Vulnerability record · CVE-2011-0922 · published 9 February 2011
CVE-2011-0922: HP Data Protector client remote code execution via EXEC_SETUP UNC path
Hp · Data Protector
The HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attackers to execute arbitrary programs. Because the client accepts this command without authentication, an attacker who can reach the client can run code in its context. The flaw is a classic improper input validation issue in a backup product that often runs with elevated privileges.
Description
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network-reachable, unauthenticated arbitrary code execution and a very high EPSS percentile make this a top remediation priority despite no KEV listing.
What it is
The HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attackers to execute arbitrary programs. Because the client accepts this command without authentication, an attacker who can reach the client can run code in its context. The flaw is a classic improper input validation issue in a backup product that often runs with elevated privileges.
Impact
An attacker gains arbitrary code execution on the affected client, with the CVSS 2.0 vector indicating complete loss of confidentiality, integrity and availability. In practice this can mean full control of the host running the Data Protector client.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity and no authentication required (Au:N), per the CVSS 2.0 vector. No user interaction is indicated by the record; the attack is delivered through an EXEC_SETUP command referencing a UNC share pathname.
Exploitation
The record is not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.64219 (99.19th percentile), indicating elevated likelihood of exploitation activity. Reference tags provide only a vendor advisory and no explicit exploit-availability tag.
What to do
- Apply the HP Data Protector update referenced in the vendor advisory (VUPEN advisory 2011/0308) as the first action.
- Restrict network access to Data Protector client and server ports to trusted management hosts only.
- Block or filter outbound SMB/UNC traffic from Data Protector clients where operationally feasible.
- Run Data Protector client services with the least privilege necessary rather than administrative rights.
- Monitor vendor advisories for this product line and retire unsupported Data Protector versions.
Detection
- Monitor Data Protector client logs for EXEC_SETUP commands referencing UNC paths.
- Alert on unexpected outbound SMB connections from Data Protector client hosts.
- Detect new or unusual process creation on Data Protector client hosts, especially child processes of the client service.
- Review network flows for external hosts reaching Data Protector client ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0922 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0922), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.