Vulnerability record · CVE-2013-2333 · published 6 June 2013
CVE-2013-2333: HP Storage Data Protector remote code execution flaw
Hp · Storage Data Protector
HP Storage Data Protector versions 6.20, 6.21, 7.00 and 7.01 contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail beyond the CVSS vector, so defenders must rely on the vendor advisory for specifics. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.
Description
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable code execution with complete impact and a very high EPSS score makes this a top remediation priority despite the thin technical detail.
What it is
HP Storage Data Protector versions 6.20, 6.21, 7.00 and 7.01 contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail beyond the CVSS vector, so defenders must rely on the vendor advisory for specifics. It matters because the flaw is network-reachable, needs no authentication and yields full confidentiality, integrity and availability impact.
Impact
An unauthenticated remote attacker can run arbitrary code on the affected Data Protector system, gaining full control of the host and any data it protects. That can mean backup data exposure, tampering or destruction, and a foothold for lateral movement.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with low complexity and no authentication required. The description does not name the specific service or port, and no user interaction is indicated.
Exploitation
The record is not listed in CISA KEV and has no exploit-tagged references, but EPSS is very high at 0.898 (99.8th percentile), suggesting elevated real-world exploitation likelihood. No public exploit detail is provided in this record.
What to do
- Apply the HP vendor advisory fix for the affected Data Protector versions (6.20, 6.21, 7.00, 7.01) as the first action.
- Restrict network access to Data Protector services to trusted management hosts and segments; do not expose them to untrusted networks.
- Place Data Protector management and cell server components behind firewalls and monitor for unexpected inbound connections.
- If patching is delayed, isolate affected servers and increase logging and monitoring on them.
- Review the vendor advisory for the specific vulnerable component and any configuration workarounds.
Detection
- Monitor Data Protector server logs and host process logs for unexpected child processes or command execution spawned by Data Protector services.
- Alert on inbound network connections to Data Protector ports from untrusted or unusual source addresses.
- Baseline normal Data Protector service behavior and flag anomalies such as new listening sockets or outbound connections from the backup server.
- Correlate host EDR telemetry on Data Protector servers for suspicious process creation, file writes or privilege changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2333 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2333), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.