CVE-2011-0921
Estado: ModificadaAlta (10)—
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 11%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://www.securityfocus.com/bid/46234
- http://www.vupen.com/english/advisories/2011/0308
- http://zerodayinitiative.com/advisories/ZDI-11-057/
- http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
- http://marc.info/?l=bugtraq&m=130391284726795&w=2
- http://www.securityfocus.com/bid/46234
- http://www.vupen.com/english/advisories/2011/0308
- http://zerodayinitiative.com/advisories/ZDI-11-057/
JSON original (NVD)
Mostrar
{
"id": "CVE-2011-0921",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-02-09T01:00:09.557",
"references": [
{
"url": "http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=130391284726795&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/46234",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0308",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://zerodayinitiative.com/advisories/ZDI-11-057/",
"source": "cve@mitre.org"
},
{
"url": "http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=130391284726795&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/46234",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0308",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://zerodayinitiative.com/advisories/ZDI-11-057/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username."
},
{
"lang": "es",
"value": "crs.exe de Cell Manager Service en el cliente de HP Data Protector no valida correctamente las credenciales asociadas con el nombre de host, dominio y nombre de usuario, que permite a atacantes remotos ejecutar código de su elección mediante el envío de datos sin especificar a través de TCP, relacionado con el cliente webreporting, el dominio del applet y el nombre de usuario Java."
}
],
"lastModified": "2026-06-16T23:28:19.070",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA2D6151-9F6C-4A0B-8A46-E53E65AFADA3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}