CVE-2016-2006: Critical severity hp storage data protector vulnerability
Published Apr 21, 2016
·Updated
HPE Data Protector before 7.03108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3353.
Affected Software
3 affected components
HP Data Protector>=7.0<7.03_108
HP Data Protector>=8.0<8.15
HP Data Protector>=9.0<9.06
Event History
Apr 21, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2006?
CVE-2016-2006 has a critical severity rating, enabling remote code execution for attackers.
2
How do I fix CVE-2016-2006?
To fix CVE-2016-2006, upgrade HPE Data Protector to version 7.03_108 or later, 8.15 or later, or 9.06 or later.
3
What software is affected by CVE-2016-2006?
CVE-2016-2006 affects HPE Data Protector versions prior to 7.03_108, 8.x before 8.15, and 9.x before 9.06.
4
What type of vulnerability is CVE-2016-2006?
CVE-2016-2006 is a remote code execution vulnerability that allows attackers to execute arbitrary code.
5
Who are the potential attackers in CVE-2016-2006?
CVE-2016-2006 allows remote attackers to exploit the vulnerability without authentication.