CVE-2007-2280

Description

Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
71.004

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2007-2280 ,CVE-2007-2281 are affected in openview_storage_data_protector 6.0NCM
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2007-2280)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234