Vulnerability record · CVE-2011-0923 · published 9 February 2011
CVE-2011-0923: HP Data Protector client EXEC_CMD input validation flaw allows remote code execution
Hp · Data Protector
The HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied to the local bin directory. Because the flaw is reachable over the network without authentication and yields full confidentiality, integrity and availability impact, it is a severe remote code execution issue for any exposed Data Protector client.
Description
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with complete impact and very high EPSS probability makes this a critical exposure despite the absence of KEV listing.
What it is
The HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied to the local bin directory. Because the flaw is reachable over the network without authentication and yields full confidentiality, integrity and availability impact, it is a severe remote code execution issue for any exposed Data Protector client.
Impact
An attacker can execute arbitrary Perl code on the affected client, gaining the privileges of the Data Protector process and potentially full control of the host.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity and no authentication (Au:N), and the description indicates no user interaction is required; the crafted EXEC_CMD command is sent to the Data Protector client.
Exploitation
No KEV listing and no ransomware association are recorded, but EPSS is very high (0.81, 99.6th percentile), indicating strong likelihood of exploitation activity; reference tags are mostly empty with only a vendor advisory noted.
What to do
- Apply the HP Data Protector security update or upgrade to a fixed release as soon as possible.
- Restrict network access to Data Protector client ports to trusted management hosts only.
- Segment backup infrastructure so Data Protector clients cannot be reached from general user or internet-facing networks.
- Monitor and audit EXEC_CMD usage and the local bin directory for unexpected Perl execution.
- Where patching is delayed, consider disabling or tightly controlling the affected client command interface.
Detection
- Alert on unexpected EXEC_CMD traffic to Data Protector clients from untrusted source addresses.
- Monitor for Perl interpreter processes spawned by the Data Protector client service.
- Watch for new or modified files in the Data Protector local bin directory.
- Correlate Data Protector client logs with host process creation events for anomalous command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0923 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0923), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.