← Vulnerability feed

Vulnerability record · CVE-2016-2004 · published 21 April 2016

CVE-2016-2004: HPE Data Protector missing authentication allows remote code execution

Hp · Data Protector

HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 expose a critical function without authentication, letting remote attackers execute arbitrary code via unspecified vectors. The flaw is an incomplete fix for CVE-2014-2623, so the same class of exposure persisted after the earlier patch. With a CVSS 3.0 score of 9.8 and a very high EPSS probability, this is a serious unauthenticated RCE risk for exposed Data Protector deployments.

9.8 CVSS 3.0 Critical EPSS 94% · top 0.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.0 base score, v2 9.3
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit code, and a 99.8th percentile EPSS probability makes this an urgent patching priority.

What it is

HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 expose a critical function without authentication, letting remote attackers execute arbitrary code via unspecified vectors. The flaw is an incomplete fix for CVE-2014-2623, so the same class of exposure persisted after the earlier patch. With a CVSS 3.0 score of 9.8 and a very high EPSS probability, this is a serious unauthenticated RCE risk for exposed Data Protector deployments.

Impact

An unauthenticated remote attacker can execute arbitrary code on the affected Data Protector system, likely with the privileges of the vulnerable service. That gives full control of the host and any data or backup infrastructure it manages.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector. The description attributes the issue to a lack of authentication on a critical function, so any network-reachable Data Protector service is in scope.

Exploitation

Public exploit code exists, as multiple references are tagged Exploit (Packet Storm and Exploit-DB entries). The CVE is not listed in CISA KEV, but EPSS is 0.94251 (99.8th percentile), indicating very high predicted exploitation activity.

What to do

  • Upgrade Data Protector to 7.03_108, 8.15, 9.06 or later as specified in the HPE advisory; treat the fix as the only complete remediation since the prior CVE-2014-2623 patch was incomplete.
  • Restrict network access to Data Protector services to trusted management hosts and segments; do not expose them to untrusted networks or the internet.
  • Audit for any remaining pre-fix installations, including 7.x, 8.x and 9.x builds below the fixed versions, and prioritize them for upgrade.
  • Monitor and log authentication and command activity on Data Protector hosts to catch anomalous execution attempts.
  • If immediate upgrade is not possible, isolate affected systems behind strict firewall rules and compensating controls until patching is complete.

Detection

  • Monitor network traffic to Data Protector service ports for unexpected or unauthenticated command execution attempts.
  • Review host process and command-line telemetry on Data Protector servers for suspicious child processes spawned by the service.
  • Correlate IDS/IPS alerts with the public exploit signatures referenced in Packet Storm and Exploit-DB entries.
  • Audit Data Protector version inventory to identify hosts still running builds below 7.03_108, 8.15 or 9.06.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2004 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0921Hp data protector improper input validation vulnerabilitycrs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, a…EPSS 11%10.0CVE-2011-0922HP Data Protector client remote code execution via EXEC_SETUP UNC pathThe HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attacker…EPSS 64%analysed10.0CVE-2011-0923HP Data Protector client EXEC_CMD input validation flaw allows remote code executionThe HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied t…EPSS 81%analysed10.0CVE-2011-0924Hp data protector improper input validation vulnerabilityThe client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute …EPSS 4.6%9.8CVE-2017-5807Hp data protector memory buffer overflow vulnerabilityA Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.EPSS 22%9.8CVE-2016-2008Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 10%9.8CVE-2016-2007Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2006Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2016-2004), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.