Vulnerability record · CVE-2013-2347 · published 4 January 2014
CVE-2013-2347: HP Storage Data Protector OmniInet.exe remote command execution
Hp · Storage Data Protector
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X mishandles a crafted EXEC_BAR packet sent to TCP port 5555, allowing remote command execution or denial of service. The flaw is remotely reachable and unauthenticated, making it a serious risk to exposed backup infrastructure.
Description
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10 and high EPSS probability on a network-exposed service.
What it is
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X mishandles a crafted EXEC_BAR packet sent to TCP port 5555, allowing remote command execution or denial of service. The flaw is remotely reachable and unauthenticated, making it a serious risk to exposed backup infrastructure.
Impact
An attacker can execute arbitrary commands on the affected host or crash the service, potentially gaining full control of the backup server and the data it manages.
Attack surface
Reached over the network via a crafted EXEC_BAR packet to TCP port 5555; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.664, 99th percentile) and public references include an Exploit-DB entry and a ZDI advisory, indicating exploit code and technical detail are publicly available.
What to do
- Apply the HP vendor advisory patch for Storage Data Protector 6.2X as the first action.
- Restrict network access to TCP port 5555 to trusted management hosts only.
- Segment backup servers from general user and internet-facing networks.
- Monitor or block EXEC_BAR traffic at the perimeter if the service cannot be patched immediately.
- Review backup server logs and host integrity for signs of compromise.
Detection
- Alert on inbound connections to TCP port 5555 from untrusted sources.
- Inspect network traffic for EXEC_BAR packets or anomalous OmniInet.exe protocol activity.
- Monitor for unexpected child processes spawned by OmniInet.exe.
- Check for service crashes or restarts of the Backup Client Service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://ddilabs.blogspot.com/2014/02/fun-with-hp-data-protector-execbar.html | Permissions Required |
| http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03822422 | Vendor Advisory |
| http://www.exploit-db.com/exploits/32164 | Broken Link |
| http://www.zerodayinitiative.com/advisories/ZDI-14-008/ | Third Party Advisory |
| http://ddilabs.blogspot.com/2014/02/fun-with-hp-data-protector-execbar.html | Permissions Required |
| http://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?docId=emr_na-c03822422 | Vendor Advisory |
| http://www.exploit-db.com/exploits/32164 | Broken Link |
| http://www.zerodayinitiative.com/advisories/ZDI-14-008/ | Third Party Advisory |
Track CVE-2013-2347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2347), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.