CVE-2011-0923

HP Data Protector - Remote Code Execution via EXEC_CMD Argument Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2011-0923. PoCs published by Metasploit, fdiskyou, Alessandro Di Pinto & Claudio Moletta, including Metasploit module auxiliary/admin/hp/hp_data_protector_cmd.

AI-analyzed exploit summary This Metasploit module exploits CVE-2011-0923 in HP Data Protector 6.10/6.11 by sending a malformed packet to port 5555, leveraging the EXEC_CMD vulnerability to achieve remote code execution as root via directory traversal to /bin/sh.

Description

The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."

Exploits (7)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/18521

This Metasploit module exploits CVE-2011-0923 in HP Data Protector 6.10/6.11 by sending a malformed packet to port 5555, leveraging the EXEC_CMD vulnerability to achieve remote code execution as root via directory traversal to /bin/sh.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.10/6.11
No auth needed
Prerequisites: Network access to TCP port 5555 on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by fdiskyou · pythonremotewindows
https://www.exploit-db.com/exploits/17339

This exploit leverages a directory traversal vulnerability in HP Data Protector Client to execute arbitrary commands (e.g., ipconfig.exe) remotely. The payload constructs a malicious path to traverse directories and execute a system command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HP Data Protector Client 6.11
No auth needed
Prerequisites: Network access to the target's HP Data Protector Client service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Alessandro Di Pinto & Claudio Moletta · pythonremotewindows
https://www.exploit-db.com/exploits/27400

This exploit leverages a vulnerability in HP Data Protector to execute arbitrary commands via a crafted packet sent to the target service. It bypasses limitations of existing exploits by using the installed Perl interpreter to execute commands with arguments.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector A.06.20
No auth needed
Prerequisites: Network access to the target service · HP Data Protector installed with Perl interpreter
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by SZ · bashremotelinux
https://www.exploit-db.com/exploits/17648

This exploit targets a remote command execution vulnerability in HP Data Protector (CVE-2011-0923) by sending a crafted shellcode payload via netcat to a specified host and port. The shellcode is designed to traverse directories and execute arbitrary commands as root.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 0.9
No auth needed
Prerequisites: network access to the target host and port · HP Data Protector service running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Adrian Puente Z. · bashremotehp-ux
https://www.exploit-db.com/exploits/17614

This exploit targets a remote command execution vulnerability in HP Data Protector on HPUX systems. It sends a crafted shellcode payload followed by a command to a specified host and port using netcat.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector (version 0.9)
No auth needed
Prerequisites: network access to the target host and port · vulnerable version of HP Data Protector running on HPUX
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by ch0ks, c4an, wireghoul, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/hp/hp_data_protector_cmd.rb

This Metasploit module exploits HP Data Protector 6.1 by sending a crafted EXEC_CMD packet to the omniinet process, triggering arbitrary command execution via CreateProcess() when the specified file is found. The exploit leverages a path traversal technique to execute commands under the C:\ directory.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HP Data Protector 6.1
No auth needed
Prerequisites: Network access to the target's omniinet process (port 5555)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by ch0ks, c4an, wireghoul, Javier Ignacio · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/hp_data_protector_cmd_exec.rb

This Metasploit module exploits a vulnerability in HP Data Protector 6.10/6.11/6.20 on Linux, allowing unauthenticated remote code execution via the EXEC_CMD command. It constructs a malicious packet to traverse to /bin/sh and execute arbitrary commands as root.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.10/6.11/6.20 on Linux
No auth needed
Prerequisites: Network access to the target on port 5555
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=130391284726795&w=2
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8261
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0308
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8323
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-11-055/
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8329
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46234

Scores

EPSS 0.8989
EPSS Percentile 99.6%

Details

CWE
CWE-20
Status published
Products (1)
hp/data_protector
Published Feb 09, 2011
Tracked Since Feb 18, 2026