CVE-2014-2623

EXPLOITED

HP Storage Data Protector 8.x - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-2623 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 4 public exploits from researchers including Metasploit, Juttikhun Khamchaiyaphum, Polunchis, including a Metasploit module exploits/windows/misc/hp_dataprotector_cmd_exec.

AI-analyzed exploit summary This Metasploit module exploits CVE-2014-2623, a remote command execution vulnerability in HP Data Protector 8.10. It sends a crafted request with opcode 28 to the OmniInet service on TCP/5555, executing arbitrary commands via rundll32.exe and a fake SMB server.

Description

Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/36304

This Metasploit module exploits CVE-2014-2623, a remote command execution vulnerability in HP Data Protector 8.10. It sends a crafted request with opcode 28 to the OmniInet service on TCP/5555, executing arbitrary commands via rundll32.exe and a fake SMB server.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 8.10
No auth needed
Prerequisites: Network access to TCP/5555 · SMB server setup for payload delivery
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Juttikhun Khamchaiyaphum · pythonremotehp-ux
https://www.exploit-db.com/exploits/35961

This exploit targets a remote command execution vulnerability in HP Data Protector 8.x by sending a crafted packet to a specified port. The payload includes a command injection mechanism that leverages a buffer overflow to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 8.x
No auth needed
Prerequisites: Network access to the target system · HP Data Protector 8.x running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Polunchis · pythonremotewindows
https://www.exploit-db.com/exploits/34066

This exploit targets HP Data Protector Manager 8.10, allowing remote command execution via a crafted packet sent to TCP port 5555. It includes functionality to either execute arbitrary commands or add a user to the Administrators group.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector Manager 8.10
No auth needed
Prerequisites: Network access to TCP port 5555 on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Christian Ramirez, Henoch Barrera · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/hp_dataprotector_cmd_exec.rb

This Metasploit module exploits a remote command execution vulnerability in HP Data Protector 8.10 by sending a crafted request with opcode 28 to the OmniInet service on TCP/5555. It executes arbitrary commands via rundll32.exe and delivers the payload through a fake SMB server.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Data Protector 8.10
No auth needed
Prerequisites: Network access to TCP/5555 on the target · SMB server setup for payload delivery
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030583
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36304
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34066/
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/109069
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35961

Scores

EPSS 0.8939
EPSS Percentile 99.8%

Details

VulnCheck KEV 2018-06-06
Status published
Products (2)
hp/storage_data_protector 8.0 (4 CPE variants)
hp/storage_data_protector 8.10 (4 CPE variants)
Published Jul 18, 2014
Tracked Since Feb 18, 2026