Vulnerability record · CVE-2012-2020 · published 11 July 2012
CVE-2012-2020: HP Operations Agent remote code execution flaw
Hp · Operations Agent
HP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, so the exact flaw cannot be characterized beyond its outcome. It matters because the affected agent is a management component and the vendor rates the impact as complete loss of confidentiality, integrity and availability.
Description
Unspecified vulnerability in HP Operations Agent before 11.03.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1326.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full impact, combined with a high EPSS percentile, warrants urgent remediation despite the thin technical detail.
What it is
HP Operations Agent before 11.03.12 contains an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no detail on the vulnerable component or mechanism, so the exact flaw cannot be characterized beyond its outcome. It matters because the affected agent is a management component and the vendor rates the impact as complete loss of confidentiality, integrity and availability.
Impact
An unauthenticated remote attacker can run arbitrary code on the host running the agent, gaining full control of that system. Given the agent's role, that host may also expose managed infrastructure.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not identify which service, port or protocol is involved.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation activity is documented in the references, which are vendor advisories only. EPSS is high at 0.647 (99.2nd percentile), suggesting elevated predicted likelihood, but that is a model estimate, not confirmed exploitation.
What to do
- Upgrade HP Operations Agent to version 11.03.12 or later as directed by the vendor advisory.
- If immediate upgrade is not possible, restrict network access to agent listeners to trusted management servers only.
- Segment or firewall hosts running the agent so it is not reachable from untrusted networks.
- Inventory all deployments of HP Operations Agent to confirm which instances remain below 11.03.12.
- Monitor vendor channels for any updated advisory or patch superseding 11.03.12.
Detection
- Audit installed HP Operations Agent versions across the estate and flag anything below 11.03.12.
- Monitor network traffic to agent ports for connections from unexpected or external source addresses.
- Watch for unexpected child processes spawned by the agent service on managed hosts.
- Review host logs for anomalous process creation or outbound connections originating from the agent.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03397769 | Vendor Advisory |
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03397769 | Vendor Advisory |
Track CVE-2012-2020 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-2020), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.