← Vulnerability feed

Vulnerability record · CVE-2012-2019 · published 11 July 2012

CVE-2012-2019: HP Operations Agent remote code execution flaw

Hp · Operations Agent

HP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors, tracked as ZDI-CAN-1325. The record gives no root cause, affected component, or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication, and yields full confidentiality, integrity, and availability impact.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full impact, combined with a 99th-percentile EPSS score, warrants critical priority despite the thin technical detail.

What it is

HP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors, tracked as ZDI-CAN-1325. The record gives no root cause, affected component, or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication, and yields full confidentiality, integrity, and availability impact.

Impact

A remote, unauthenticated attacker can execute arbitrary code on the host running the affected agent, gaining full control of that system. Given the agent's role, compromise could also expose managed infrastructure it communicates with.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The specific protocol, port, or interface is not stated in the record.

Exploitation

The record shows no CISA KEV listing and no exploit references, but EPSS is 0.64685 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. Actual in-the-wild exploitation is not confirmed by the supplied data.

What to do

  • Upgrade HP Operations Agent to version 11.03.12 or later as directed by the vendor advisory.
  • If immediate patching is not possible, restrict network access to agent listener ports to trusted management hosts only.
  • Segment or firewall agent hosts so they are not reachable from untrusted networks.
  • Monitor the vendor advisory for updated guidance, since the record lacks technical detail on the vulnerable component.
  • Inventory all HP Operations Agent deployments to confirm which hosts still run versions before 11.03.12.

Detection

  • Review agent host logs for unexpected process creation or child processes spawned by the Operations Agent service.
  • Baseline and alert on network connections to agent listener ports from hosts outside the management subnet.
  • Hunt for unusual outbound connections or file writes originating from the agent process on managed hosts.
  • Correlate agent service restarts or crashes with anomalous activity on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2020HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no deta…EPSS 65%analysed10.0CVE-2010-0444Hp operations agent vulnerabilityHP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute a…EPSS 8.6%7.5CVE-2017-3733Openssl improper input validation vulnerabilityDuring a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this…EPSS 13%7.5CVE-2010-3004Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.EPSS 5.3%6.8CVE-2010-3005Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.EPSS 0.28%6.4CVE-2011-2608Hp openview performance agent improper input validation vulnerabilityovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60…EPSS 4.8%4.4CVE-2014-2630Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.EPSS 7.1%4.3CVE-2014-2647Hp operations agent cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allow…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2012-2019), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.