Vulnerability record · CVE-2012-2019 · published 11 July 2012
CVE-2012-2019: HP Operations Agent remote code execution flaw
Hp · Operations Agent
HP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors, tracked as ZDI-CAN-1325. The record gives no root cause, affected component, or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication, and yields full confidentiality, integrity, and availability impact.
Description
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1325.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full impact, combined with a 99th-percentile EPSS score, warrants critical priority despite the thin technical detail.
What it is
HP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors, tracked as ZDI-CAN-1325. The record gives no root cause, affected component, or attack vector detail, so defenders must rely on the vendor advisory and the CVSS vector. It matters because the flaw is network-reachable, needs no authentication, and yields full confidentiality, integrity, and availability impact.
Impact
A remote, unauthenticated attacker can execute arbitrary code on the host running the affected agent, gaining full control of that system. Given the agent's role, compromise could also expose managed infrastructure it communicates with.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The specific protocol, port, or interface is not stated in the record.
Exploitation
The record shows no CISA KEV listing and no exploit references, but EPSS is 0.64685 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. Actual in-the-wild exploitation is not confirmed by the supplied data.
What to do
- Upgrade HP Operations Agent to version 11.03.12 or later as directed by the vendor advisory.
- If immediate patching is not possible, restrict network access to agent listener ports to trusted management hosts only.
- Segment or firewall agent hosts so they are not reachable from untrusted networks.
- Monitor the vendor advisory for updated guidance, since the record lacks technical detail on the vulnerable component.
- Inventory all HP Operations Agent deployments to confirm which hosts still run versions before 11.03.12.
Detection
- Review agent host logs for unexpected process creation or child processes spawned by the Operations Agent service.
- Baseline and alert on network connections to agent listener ports from hosts outside the management subnet.
- Hunt for unusual outbound connections or file writes originating from the agent process on managed hosts.
- Correlate agent service restarts or crashes with anomalous activity on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03397769 | Vendor Advisory |
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03397769 | Vendor Advisory |
Track CVE-2012-2019 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2019), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.