← Vulnerability feed

Vulnerability record · CVE-2016-2005 · published 21 April 2016

CVE-2016-2005: Hp data protector vulnerability

Hp · Data Protector

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.

9.8 CVSS 3.0 Critical EPSS 20% · top 2.6%
9.8CVSS 3.0 base score, v2 10.0
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-2005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0921Hp data protector improper input validation vulnerabilitycrs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, a…EPSS 11%10.0CVE-2011-0922HP Data Protector client remote code execution via EXEC_SETUP UNC pathThe HP Data Protector client fails to properly validate input in an EXEC_SETUP command that references a UNC share pathname, allowing remote attacker…EPSS 64%analysed10.0CVE-2011-0923HP Data Protector client EXEC_CMD input validation flaw allows remote code executionThe HP Data Protector client fails to validate EXEC_CMD arguments, letting a remote attacker run arbitrary Perl code through a crafted command tied t…EPSS 81%analysed10.0CVE-2011-0924Hp data protector improper input validation vulnerabilityThe client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute …EPSS 4.6%9.8CVE-2017-5807Hp data protector memory buffer overflow vulnerabilityA Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.EPSS 22%9.8CVE-2016-2008Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 10%9.8CVE-2016-2007Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%9.8CVE-2016-2006Hp data protector vulnerabilityHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, a…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2016-2005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.