CVE-2006-4201
Estado: ModificadaAlta (7.5)—
Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 10%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00742778
- http://jvn.jp/niscc/NISCC-412866/
- http://secunia.com/advisories/21485
- http://securitytracker.com/id?1016688
- http://www.kb.cert.org/vuls/id/673228
- http://www.securityfocus.com/bid/19495
- http://www.uniras.gov.uk/niscc/docs/re-20060811-00547.pdf?lang=en
- http://www.vupen.com/english/advisories/2006/3273
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28348
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00742778
- http://jvn.jp/niscc/NISCC-412866/
- http://secunia.com/advisories/21485
- http://securitytracker.com/id?1016688
- http://www.kb.cert.org/vuls/id/673228
- http://www.securityfocus.com/bid/19495
- http://www.uniras.gov.uk/niscc/docs/re-20060811-00547.pdf?lang=en
- http://www.vupen.com/english/advisories/2006/3273
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28348
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-4201",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-08-17T21:04:00.000",
"references": [
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00742778",
"source": "cve@mitre.org"
},
{
"url": "http://jvn.jp/niscc/NISCC-412866/",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/21485",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1016688",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/673228",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/19495",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.uniras.gov.uk/niscc/docs/re-20060811-00547.pdf?lang=en",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3273",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28348",
"source": "cve@mitre.org"
},
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00742778",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvn.jp/niscc/NISCC-412866/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/21485",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1016688",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/673228",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/19495",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.uniras.gov.uk/niscc/docs/re-20060811-00547.pdf?lang=en",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/3273",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28348",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation."
},
{
"lang": "es",
"value": "Vulnerabilidad no especificada en el agente de copia de respaldo (backup agent) y el Cell Manager de HP OpenView Storage Data Protector 5.1 y 5.5 anteiror al 10/08/2006 permite a atacantes remotos ejecutar código de su elección en un agente a través de vectores no especificados relacionados con la autenticación y la validación de entrada."
}
],
"lastModified": "2026-06-16T22:28:36.237",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:openview_storage_data_protector:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6BFBB63-DFBA-4ECF-B62F-23069125F627",
"versionEndIncluding": "5.5"
},
{
"criteria": "cpe:2.3:a:hp:openview_storage_data_protector:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DC36ADB-81B5-4DA8-A344-756CDF563B0A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "A patch is available for affected versions."
}