← Vulnerability feed

Vulnerability record · CVE-2013-2347 · published 4 January 2014

CVE-2013-2347: HP Storage Data Protector OmniInet.exe remote command execution

Hp · Storage Data Protector

The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X mishandles a crafted EXEC_BAR packet sent to TCP port 5555, allowing remote command execution or denial of service. The flaw is remotely reachable and unauthenticated, making it a serious risk to exposed backup infrastructure.

10.0 CVSS 2.0 High EPSS 66% · top 0.7%
10.0CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10 and high EPSS probability on a network-exposed service.

What it is

The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X mishandles a crafted EXEC_BAR packet sent to TCP port 5555, allowing remote command execution or denial of service. The flaw is remotely reachable and unauthenticated, making it a serious risk to exposed backup infrastructure.

Impact

An attacker can execute arbitrary commands on the affected host or crash the service, potentially gaining full control of the backup server and the data it manages.

Attack surface

Reached over the network via a crafted EXEC_BAR packet to TCP port 5555; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.664, 99th percentile) and public references include an Exploit-DB entry and a ZDI advisory, indicating exploit code and technical detail are publicly available.

What to do

  • Apply the HP vendor advisory patch for Storage Data Protector 6.2X as the first action.
  • Restrict network access to TCP port 5555 to trusted management hosts only.
  • Segment backup servers from general user and internet-facing networks.
  • Monitor or block EXEC_BAR traffic at the perimeter if the service cannot be patched immediately.
  • Review backup server logs and host integrity for signs of compromise.

Detection

  • Alert on inbound connections to TCP port 5555 from untrusted sources.
  • Inspect network traffic for EXEC_BAR packets or anomalous OmniInet.exe protocol activity.
  • Monitor for unexpected child processes spawned by OmniInet.exe.
  • Check for service crashes or restarts of the Backup Client Service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2347 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-2623HP Storage Data Protector 8.x remote code execution flawCVE-2014-2623 is an unspecified vulnerability in HP Storage Data Protector 8.x that allows remote attackers to execute arbitrary code. The record giv…EPSS 89%analysed10.0CVE-2013-2344Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2345Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2346Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2348Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2349Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2350Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-6194HP Storage Data Protector remote code execution and denial of serviceHP Storage Data Protector 6.2X contains an unspecified vulnerability that lets remote attackers execute arbitrary code or cause a denial of service. …EPSS 66%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.