← Vulnerability feed

Vulnerability record · CVE-2012-2020 · published 11 July 2012

CVE-2012-2020: HP Operations Agent remote code execution flaw

Hp · Operations Agent

HP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, so the exact flaw cannot be characterized beyond its outcome. It matters because the affected agent is a management component and the vendor rates the impact as complete loss of confidentiality, integrity and availability.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full impact, combined with a high EPSS percentile, warrants urgent remediation despite the thin technical detail.

What it is

HP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, so the exact flaw cannot be characterized beyond its outcome. It matters because the affected agent is a management component and the vendor rates the impact as complete loss of confidentiality, integrity and availability.

Impact

An unauthenticated remote attacker can run arbitrary code on the host running the agent, gaining full control of that system. Given the agent's role, that host may also expose managed infrastructure.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not identify which service, port or protocol is involved.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation activity is documented in the references, which are vendor advisories only. EPSS is high at 0.647 (99.2nd percentile), suggesting elevated predicted likelihood, but that is a model estimate, not confirmed exploitation.

What to do

  • Upgrade HP Operations Agent to version 11.03.12 or later as directed by the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to agent listeners to trusted management servers only.
  • Segment or firewall hosts running the agent so it is not reachable from untrusted networks.
  • Inventory all deployments of HP Operations Agent to confirm which instances remain below 11.03.12.
  • Monitor vendor channels for any updated advisory or patch superseding 11.03.12.

Detection

  • Audit installed HP Operations Agent versions across the estate and flag anything below 11.03.12.
  • Monitor network traffic to agent ports for connections from unexpected or external source addresses.
  • Watch for unexpected child processes spawned by the agent service on managed hosts.
  • Review host logs for anomalous process creation or outbound connections originating from the agent.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-2020 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-2019HP Operations Agent remote code execution flawHP Operations Agent before 11.03.12 contains an unspecified vulnerability that allows remote attackers to execute arbitrary code via unknown vectors,…EPSS 65%analysed10.0CVE-2010-0444Hp operations agent vulnerabilityHP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute a…EPSS 8.6%7.5CVE-2017-3733Openssl improper input validation vulnerabilityDuring a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this…EPSS 13%7.5CVE-2010-3004Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.EPSS 5.3%6.8CVE-2010-3005Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.EPSS 0.28%6.4CVE-2011-2608Hp openview performance agent improper input validation vulnerabilityovbbccb.exe 6.20.50.0 and other versions in HP OpenView Performance Agent 4.70 and 5.0; and Operations Agent 11.0, 8.60.005, 8.60.006, 8.60.007, 8.60…EPSS 4.8%4.4CVE-2014-2630Hp operations agent vulnerabilityUnspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.EPSS 7.1%4.3CVE-2014-2647Hp operations agent cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allow…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2012-2020), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.