← Vulnerability feed

Vulnerability record · CVE-2011-0923 · published 9 February 2011

CVE-2011-0923: HP Data Protector client EXEC_CMD input validation flaw allows remote code execution

Hp · Data Protector

The HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied to the local bin directory. Because the flaw is reachable over the network without authentication and yields full confidentiality, integrity and availability impact, it is a severe remote code execution issue for any exposed Data Protector client.

10.0 CVSS 2.0 High EPSS 81% · top 0.4% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable remote code execution with complete impact and very high EPSS probability makes this a critical exposure despite the absence of KEV listing.

What it is

The HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied to the local bin directory. Because the flaw is reachable over the network without authentication and yields full confidentiality, integrity and availability impact, it is a severe remote code execution issue for any exposed Data Protector client.

Impact

An attacker can execute arbitrary Perl code on the affected client, gaining the privileges of the Data Protector process and potentially full control of the host.

Attack surface

The vulnerability is network-reachable (AV:N) with low complexity and no authentication (Au:N), and the description indicates no user interaction is required; the crafted EXEC_CMD command is sent to the Data Protector client.

Exploitation

No KEV listing and no ransomware association are recorded, but EPSS is very high (0.81, 99.6th percentile), indicating strong likelihood of exploitation activity; reference tags are mostly empty with only a vendor advisory noted.

What to do

  • Apply the HP Data Protector security update or upgrade to a fixed release as soon as possible.
  • Restrict network access to Data Protector client ports to trusted management hosts only.
  • Segment backup infrastructure so Data Protector clients cannot be reached from general user or internet-facing networks.
  • Monitor and audit EXEC_CMD usage and the local bin directory for unexpected Perl execution.
  • Where patching is delayed, consider disabling or tightly controlling the affected client command interface.

Detection

  • Alert on unexpected EXEC_CMD traffic to Data Protector clients from untrusted source addresses.
  • Monitor for Perl interpreter processes spawned by the Data Protector client service.
  • Watch for new or modified files in the Data Protector local bin directory.
  • Correlate Data Protector client logs with host process creation events for anomalous command execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0923 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0921Hp data protector improper input validation vulnerabilitycrs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, a…EPSS 11%10.0CVE-2011-0922HP Data Protector client remote code execution via EXEC_SETUP UNC pathThe HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attacker…EPSS 64%analysed10.0CVE-2011-0924Hp data protector improper input validation vulnerabilityThe client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute …EPSS 4.6%9.8CVE-2017-5807Hp data protector memory buffer overflow vulnerabilityA Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.EPSS 22%9.8CVE-2016-2008Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 10%9.8CVE-2016-2007Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2006Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2005Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2011-0923), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.