← Vulnerability feed

Vulnerability record · CVE-2011-2608 · published 1 July 2011

CVE-2011-2608: Hp openview performance agent improper input validation vulnerability

Hp · Openview Performance Agent

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

6.4 CVSS 2.0 Medium EPSS 4.8% · top 8.4% CWE-20 · Improper input validation
6.4CVSS 2.0 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

ovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60.008, 8.60.501, and 8.53; allows remote attackers to delete arbitrary files via a full pathname in the File field in a Register command.

AV:N/AC:L/Au:N/C:N/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2608 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2019HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors,…EPSS 65%analysed10.0CVE-2012-2020HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no deta…EPSS 65%analysed10.0CVE-2010-0444Hp operations agent vulnerabilityHP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute a…EPSS 8.6%9.3CVE-2008-4420Hp openview performance agent memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP…EPSS 5.7%7.5CVE-2017-3733Openssl improper input validation vulnerabilityDuring a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this…EPSS 13%7.5CVE-2010-3004Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.EPSS 5.3%6.8CVE-2010-3005Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.EPSS 0.28%4.4CVE-2014-2630Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.EPSS 7.1%

Source: NIST National Vulnerability Database (record CVE-2011-2608), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.