CVE-2013-6194

HP Storage Data Protector 6.2X - Remote Code Execution or Denial of Service

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-6194. PoCs published by Metasploit, Brian Gorenc, juan vazquez, including Metasploit module exploits/windows/misc/hp_dataprotector_traversal.

AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in HP Data Protector's Backup Client Service (OmniInet.exe) via opcode 42 to upload and execute a malicious payload, achieving remote code execution.

Description

Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/31181

This Metasploit module exploits a directory traversal vulnerability in HP Data Protector's Backup Client Service (OmniInet.exe) via opcode 42 to upload and execute a malicious payload, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.20 build 370
No auth needed
Prerequisites: Network access to port 5555 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by Brian Gorenc, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_dataprotector_traversal.rb

This Metasploit module exploits a directory traversal vulnerability in HP Data Protector's Backup Client Service (OmniInet.exe) via crafted packets with opcode 42. It achieves remote code execution by uploading malicious VBS and MOF files to the target system.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 6.20 build 370
No auth needed
Prerequisites: Network access to TCP port 5555 on the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/101630
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/31181

Scores

EPSS 0.6592
EPSS Percentile 99.2%

Details

Status published
Products (2)
hp/storage_data_protector 6.20 (2 CPE variants)
hp/storage_data_protector 6.21 (5 CPE variants)
Published Jan 04, 2014
Tracked Since Feb 18, 2026