Vulnerability record · CVE-2016-2004 · published 21 April 2016
CVE-2016-2004: HPE Data Protector missing authentication allows remote code execution
Hp · Data Protector
HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 expose a critical function without authentication, letting remote attackers execute arbitrary code via unspecified vectors. The flaw is an incomplete fix for CVE-2014-2623, so the same class of exposure persisted after the earlier patch. With a CVSS 3.0 score of 9.8 and a very high EPSS probability, this is a serious unauthenticated RCE risk for exposed Data Protector deployments.
Description
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit code, and a 99.8th percentile EPSS probability makes this an urgent patching priority.
What it is
HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06 expose a critical function without authentication, letting remote attackers execute arbitrary code via unspecified vectors. The flaw is an incomplete fix for CVE-2014-2623, so the same class of exposure persisted after the earlier patch. With a CVSS 3.0 score of 9.8 and a very high EPSS probability, this is a serious unauthenticated RCE risk for exposed Data Protector deployments.
Impact
An unauthenticated remote attacker can execute arbitrary code on the affected Data Protector system, likely with the privileges of the vulnerable service. That gives full control of the host and any data or backup infrastructure it manages.
Attack surface
Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector. The description attributes the issue to a lack of authentication on a critical function, so any network-reachable Data Protector service is in scope.
Exploitation
Public exploit code exists, as multiple references are tagged Exploit (Packet Storm and Exploit-DB entries). The CVE is not listed in CISA KEV, but EPSS is 0.94251 (99.8th percentile), indicating very high predicted exploitation activity.
What to do
- Upgrade Data Protector to 7.03_108, 8.15, 9.06 or later as specified in the HPE advisory; treat the fix as the only complete remediation since the prior CVE-2014-2623 patch was incomplete.
- Restrict network access to Data Protector services to trusted management hosts and segments; do not expose them to untrusted networks or the internet.
- Audit for any remaining pre-fix installations, including 7.x, 8.x and 9.x builds below the fixed versions, and prioritize them for upgrade.
- Monitor and log authentication and command activity on Data Protector hosts to catch anomalous execution attempts.
- If immediate upgrade is not possible, isolate affected systems behind strict firewall rules and compensating controls until patching is complete.
Detection
- Monitor network traffic to Data Protector service ports for unexpected or unauthenticated command execution attempts.
- Review host process and command-line telemetry on Data Protector servers for suspicious child processes spawned by the service.
- Correlate IDS/IPS alerts with the public exploit signatures referenced in Packet Storm and Exploit-DB entries.
- Audit Data Protector version inventory to identify hosts still running builds below 7.03_108, 8.15 or 9.06.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2004 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2004), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.