CVE-2013-2335: Critical severity HP Storage Data Protector Hp-ux vulnerability
Published Jun 6, 2013
·Updated
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1733.
Affected Software
22 affected components
HP Storage Data Protector Hp-ux=6.20
HP Storage Data Protector Redhat Enterprise Linux=6.20
HP Storage Data Protector Sunos=6.20
HP Storage Data Protector Suse Linux=6.20
HP Storage Data Protector Windows Server 2003=6.20
HP Storage Data Protector Windows Server 2008=6.20
HP Storage Data Protector Hp-ux=6.21
HP Storage Data Protector Redhat Enterprise Linux=6.21
HP Storage Data Protector Sunos=6.21
HP Storage Data Protector Suse Linux=6.21
HP Storage Data Protector Windows Server 2003=6.21
HP Storage Data Protector Windows Server 2008=6.21
HP Storage Data Protector Hp-ux=7.00
HP Storage Data Protector Redhat Enterprise Linux=7.00
HP Storage Data Protector Suse Linux=7.00
HP Storage Data Protector Windows Server 2003=7.00
HP Storage Data Protector Windows Server 2008=7.00
HP Storage Data Protector Hp-ux=7.01
HP Storage Data Protector Redhat Enterprise Linux=7.01
HP Storage Data Protector Suse Linux=7.01
HP Storage Data Protector Windows Server 2003=7.01
HP Storage Data Protector Windows Server 2008=7.01
Event History
Jun 6, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2335?
CVE-2013-2335 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2013-2335?
To fix CVE-2013-2335, you should upgrade to a non-vulnerable version of HP Storage Data Protector as recommended by HP.
3
What versions are affected by CVE-2013-2335?
The affected versions of HP Storage Data Protector are 6.20, 6.21, 7.00, and 7.01.
4
Who can exploit CVE-2013-2335?
CVE-2013-2335 can be exploited by remote attackers who can send specially crafted requests to the vulnerable application.
5
Is there a workaround for CVE-2013-2335 if I cannot upgrade?
Currently, there are no known effective workarounds for CVE-2013-2335, so upgrading is the recommended action.