← Vulnerability feed

Vulnerability record · CVE-2013-6194 · published 4 January 2014

CVE-2013-6194: HP Storage Data Protector remote code execution and denial of service

Hp · Storage Data Protector

HP Storage Data Protector 6.2X contains an unspecified vulnerability that lets remote attackers execute arbitrary code or cause a denial of service. The flaw is tracked as ZDI-CAN-1905 and the vendor advisory and an Exploit-DB entry exist, but the record gives no root cause, affected component or exact version detail beyond the 6.2X line.

10.0 CVSS 2.0 High EPSS 66% · top 0.7%
10.0CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, plus public exploit code and very high EPSS.

What it is

HP Storage Data Protector 6.2X contains an unspecified vulnerability that lets remote attackers execute arbitrary code or cause a denial of service. The flaw is tracked as ZDI-CAN-1905 and the vendor advisory and an Exploit-DB entry exist, but the record gives no root cause, affected component or exact version detail beyond the 6.2X line.

Impact

An unauthenticated remote attacker can run arbitrary code on the affected Data Protector host or crash it, giving full compromise of the backup server and any data or credentials it manages.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not name the specific service or port, so the exact entry point is unknown.

Exploitation

The record is not listed in CISA KEV, but EPSS is 0.65924 (99.2nd percentile) and an Exploit-DB reference tagged Exploit exists, indicating public exploit code is available and exploitation is plausible.

What to do

  • Apply the HP vendor advisory fix for Storage Data Protector 6.2X (emr_na-c03822422) or upgrade to a supported release.
  • Restrict network access to Data Protector services so only trusted management hosts can reach them; do not expose them to untrusted networks.
  • Segment backup infrastructure from general user and internet-facing networks to limit lateral movement after compromise.
  • Monitor and alert on unexpected process execution or crashes on Data Protector servers.
  • If patching is not immediately possible, consider temporary isolation of the affected server from untrusted networks.

Detection

  • Monitor Data Protector server logs and host telemetry for unexpected child processes spawned by Data Protector services.
  • Alert on service crashes or restarts of Data Protector components that could indicate denial-of-service attempts.
  • Watch network traffic to Data Protector management ports from unauthorized or external source addresses.
  • Correlate Exploit-DB 31181 activity indicators with host and network logs where feasible.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6194 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-2623HP Storage Data Protector 8.x remote code execution flawCVE-2014-2623 is an unspecified vulnerability in HP Storage Data Protector 8.x that allows remote attackers to execute arbitrary code. The record giv…EPSS 91%analysed10.0CVE-2013-2344Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2345Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2346Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2347HP Storage Data Protector OmniInet.exe remote command executionThe Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X mishandles a crafted EXEC_BAR packet sent to TCP port 5555, allowing remot…EPSS 66%analysed10.0CVE-2013-2348Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2349Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%10.0CVE-2013-2350Hp storage data protector vulnerabilityUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknow…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2013-6194), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.