CVE-2007-2280

HP OpenView Storage Data Protector 5.50 and 6.0 - Remote Code Execution via MSG_PROTOCOL Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-2280. PoCs published by Metasploit, including Metasploit module exploits/windows/misc/hp_omniinet_1.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in HP OmniInet.exe via a crafted MSG_PROTOCOL packet, allowing remote code execution with elevated privileges. It includes automatic target detection and SEH-based exploitation.

Description

Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16455

This Metasploit module exploits a stack-based buffer overflow in HP OmniInet.exe via a crafted MSG_PROTOCOL packet, allowing remote code execution with elevated privileges. It includes automatic target detection and SEH-based exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP OmniInet.exe (versions in HP OpenView Data Protector 5.50-6.10 and HP Application Recovery Manager 6.0-6.1)
No auth needed
Prerequisites: Network access to TCP port 5555 · Vulnerable version of HP OmniInet.exe
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_omniinet_1.rb

This Metasploit module exploits a stack-based buffer overflow in HP OmniInet.exe via a crafted MSG_PROTOCOL packet, allowing remote code execution with elevated privileges. It includes multiple targets for different versions of HP OpenView Data Protector and Application Recovery Manager.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP OmniInet.exe (HP OpenView Data Protector, HP Application Recovery Manager)
No auth needed
Prerequisites: Network access to the target service on port 5555
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37396
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=126106261622540&w=2
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023361
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3594

Scores

EPSS 0.7100
EPSS Percentile 98.7%

Details

CWE
CWE-119
Status published
Products (2)
hp/openview_storage_data_protector 5.50
hp/openview_storage_data_protector 6.0
Published Dec 18, 2009
Tracked Since Feb 18, 2026